CVE-2024-52012 Details
Description
Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload" API. Commonly known as a "zipslip", maliciously constructed ZIP files can use relative filepaths to write data to unanticipated parts of the filesystem. This issue affects Apache Solr: from 6.6 through 9.7.0. Users are recommended to upgrade to version 9.8.0, which fixes the issue. Users unable to upgrade may also safely prevent the issue by using Solr's "Rule-Based Authentication Plugin" to restrict access to the configset upload API, so that it can only be accessed by a trusted set of administrators/users.
A relative path traversal vulnerability has been identified in Apache Solr versions 6.6 through 9.7.0, specifically in instances running on Windows. This vulnerability allows arbitrary write access to the filesystem due to inadequate input sanitation in the 'configset upload' API. Maliciously crafted ZIP files can exploit this flaw, using relative paths to write data to unexpected locations on the filesystem. This issue is commonly referred to as a 'zipslip' vulnerability.
Users are advised to upgrade to Apache Solr version 9.8.0, which addresses this vulnerability. For those unable to upgrade, access to the 'configset upload' API can be restricted using Solr's 'Rule-Based Authentication Plugin', allowing only a trusted set of administrators or users to access the API.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/01/26/2 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/yp39pgbv4vf1746pf5yblz84lv30vfxd | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-23 | Relative Path Traversal | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache solr | >= 6.6.0, < 9.8.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 27, 2025 | Initial Analysis | [email protected] |
| Feb 6, 2025 | CVE Modified | CISA-ADP |
| Jan 27, 2025 | New CVE Received | [email protected] |
| Jan 27, 2025 | CVE Modified | CVE |