{"id":"GHSA-jq2w-w7v2-69q5","summary":"Apache Solr  vulnerable to XML Bomb","details":"Solr versions prior to 5.0.0 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it?s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.","aliases":["CVE-2019-12401"],"modified":"2024-02-21T05:20:30.290709Z","published":"2022-05-24T22:00:29Z","database_specific":{"nvd_published_at":"2019-09-10T15:15:00Z","cwe_ids":["CWE-776"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-11-08T13:23:13Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-12401"},{"type":"WEB","url":"https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-12401-XML%20Bomb-Apache%20Solr"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/SOLR-13750"},{"type":"WEB","url":"https://lists.apache.org/thread.html/048ae6e4f84a88e8856f766320b48ad91f9fca2c6f621aa2c40088fe@%3Cdev.lucene.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/0ec231c5ed8d242890e21806d25fdd47f80cc47cac278d2fc1c9c579@%3Cdev.lucene.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/1c92300643f48f13bc59b15e3f886ba62bae1798c7d4c2e5c1ece09b@%3Cannounce.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/521d10a19bfb590f86dff41820ccfb11e92281f233a12c882650931e@%3Cdev.lucene.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/60a924662ead9aeea74e8ea128d9ca935f8de925aa71b15ab2787d6a@%3Csolr-user.lucene.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/7ab5e95a1a0b4f35ffe53f1eb0cb74b4348b49d41b72ac155b843fa2@%3Cgeneral.lucene.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/db8eaca456d03c00a66cbe37548978318d424b9997e3fd7f5c65dffe@%3Cdev.lucene.apache.org%3E"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20190926-0002"},{"type":"WEB","url":"http://mail-archives.us.apache.org/mod_mbox/www-announce/201909.mbox/%3CCAECwjAXU4%3DkAo5DeUJw7Kvk67sgCmajAN7LGZQNjbjZ8gv%3DBdw%40mail.gmail.com%3E"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2019/09/10/1"}],"affected":[{"package":{"name":"org.apache.solr:solr-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.solr/solr-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.0"}]}],"versions":["1.3.0","1.4.0","1.4.1","3.1.0","3.2.0","3.3.0","3.4.0","3.5.0","3.6.0","3.6.1","3.6.2","4.0.0","4.0.0-ALPHA","4.0.0-BETA","4.1.0","4.10.0","4.10.1","4.10.2","4.10.3","4.10.4","4.2.0","4.2.1","4.3.0","4.3.1","4.4.0","4.5.0","4.5.1","4.6.0","4.6.1","4.7.0","4.7.1","4.7.2","4.8.0","4.8.1","4.9.0","4.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jq2w-w7v2-69q5/GHSA-jq2w-w7v2-69q5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}