{"id":"GHSA-wgw2-gw4v-9w4j","summary":"Improper Neutralization of Input During Web Page Generation in Apache Solr","details":"Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object.","aliases":["CVE-2014-3628"],"modified":"2024-12-07T05:24:52.153493Z","published":"2022-05-17T04:17:55Z","database_specific":{"nvd_published_at":"2015-01-06T15:59:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-07-07T22:32:22Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3628"},{"type":"WEB","url":"http://mail-archives.us.apache.org/mod_mbox/www-announce/201412.mbox/%3C54A1A7C7.2070804@apache.org%3E"}],"affected":[{"package":{"name":"org.apache.solr:solr","ecosystem":"Maven","purl":"pkg:maven/org.apache.solr/solr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.10.3"}]}],"versions":["4.0.0","4.1.0","4.10.0","4.10.1","4.10.2","4.2.0","4.2.1","4.3.0","4.3.1","4.4.0","4.5.0","4.5.1","4.6.0","4.6.1","4.7.0","4.7.1","4.7.2","4.8.0","4.8.1","4.9.0","4.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wgw2-gw4v-9w4j/GHSA-wgw2-gw4v-9w4j.json"}}],"schema_version":"1.9.0"}