Miggo Logo

CVE-2018-8026:
XML external entity expansion in org.apache.solr:solr-core

5.5

CVSS Score

Basic Information

EPSS Score
-
Published
10/17/2018
Updated
3/4/2024
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.apache.solr:solr-coremaven>= 6.0.0, < 6.6.56.6.5
org.apache.solr:solr-coremaven>= 7.0.0, < 7.4.07.4.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The analysis involved examining the patches and identifying functions that were modified to mitigate the XXE vulnerability. These functions were originally using DocumentBuilderFactory to parse XML files without proper security measures, making them vulnerable.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

T*is vuln*r**ility in *p**** Solr *.*.* to *.*.* *n* *.*.* to *.*.* r*l*t*s to *n XML *xt*rn*l *ntity *xp*nsion (XX*) in Solr *on*i* *il*s (*urr*n*y.xml, *nums*on*i*.xml r***rr** *rom s***m*.xml, TIK* p*rs**ont*xt *on*i* *il*). In ***ition, Xin*lu**

Reasoning

T** *n*lysis involv** *x*minin* t** p*t***s *n* i**nti*yin* *un*tions t**t w*r* mo*i*i** to miti**t* t** XX* vuln*r**ility. T**s* *un*tions w*r* ori*in*lly usin* *o*um*nt*uil**r***tory to p*rs* XML *il*s wit*out prop*r s**urity m**sur*s, m*kin* t**m