← back
CVE-2017-3164

CVE-2017-3164

EPSS 19.4%
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →