A GitHub security researcher, S00pY, discovered and published a vulnerability vulnerability in the open-source platform Apache Solr. It is a critical , which allows remote command execution. At present, the company behind Apache Solr has not released an update to address the vulnerability.
Vulnerability information
How can the vulnerability be exploited by malicious hackers?
- An attacker could exploit the vulnerability and gain direct access to the Solr console. If they gain access, they could make changes to the node's configuration file by sending a POST request such as /nodename/config.
- Apache Solr comes with the VelocityResponseWriter plugin by default. The plugin has the setting params.resource.loader.enabled, which is false by default. When params.resource.loader.enabled is changed to true, it is possible to send specially crafted packets. When this change is made, a hacker who has gained access can execute commands on the server remotely.

Which versions are affected by the vulnerability?
According to the checks that have been carried out so far, the versions affected are Apache Solr 7.x to 8.2.0.
How will the vulnerability be addressed?
As mentioned above, the company has not yet released a patch to fix the critical vulnerability. For now, users of the Apache Solr platform should implement basic security and be on the lookout to update systems as soon as an update is released.
