UBUNTU-CVE-2019-0193
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-0193
UBUNTU-CVE-2019-0193
Summary:
Details: In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.
References: https://ubuntu.com/security/CVE-2019-0193, https://issues.apache.org/jira/browse/SOLR-13669, https://www.cve.org/CVERecord?id=CVE-2019-0193, https://www.cisa.gov/known-exploited-vulnerabilities-catalog, https://ubuntu.com/security/notices/USN-7283-1
Affected packages
Package
Name: lucene-solr
Purl: pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu0.1~esm4?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
