Apache Solr DataImportHandler Code Injection Vulnerability
The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
CISA entryApache · AUTOMATIC DISCOVERY
Apache Solr is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
This record passed BlackTree's automatic primary-source checks with a confidence score of 82. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.
This discovery does not establish a product-specific support or retirement date. A missing date does not mean support continues.
Apache Solr is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Used to provide application, infrastructure or operational services to other systems and users.
Deployed on servers, virtual machines, containers or managed infrastructure.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .
| Product | Apache Solr |
|---|---|
| Release | Lifecycle policy |
| Start or release | Not extracted |
| Lifecycle boundary | Continuous or not dated in the source |
| Date precision | Unknown |
These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
CISA entryThe Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
CISA entryOSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
No package advisories have been linked for this product identity.
This is not evidence that the product has no vulnerabilities.
The solr-VERSION.zip or solr-VERSION.tgz files (where VERSION is the version number of the release, e.g. 10.0.0 ) contain Apache Solr, html documentation and a tutorial. | The solr-VERSION-src.tgz file contains the full source code for that version. | About versions and support ¶ | Apache Solr is under active development with frequent feature releases on the current major version. The previous major version will see occasional critical security- or bug fixes releases. Older versions are considered EOL (End Of Life) and will not be further updated. For this reason it may also be difficult to obtain community support for EOL versions. | Large changes or changes that break compatibility with existing functionality are normally only included in the next major version. | For more about versions and upgrading Solr, see the Reference Guide chapter “Upgrade Notes” and "System Requirements" . | Features
Publisher identity used by product-specific official-source collectors.
Open official vendor source