Vulnerability Details CVE-2017-3164
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.571
EPSS Ranking 98.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-3164
-
cpe:2.3:a:apache:solr:1.3.0
-
cpe:2.3:a:apache:solr:1.4.0
-
cpe:2.3:a:apache:solr:1.4.1
-
cpe:2.3:a:apache:solr:3.1
-
cpe:2.3:a:apache:solr:3.1.0
-
cpe:2.3:a:apache:solr:3.2
-
cpe:2.3:a:apache:solr:3.2.0
-
cpe:2.3:a:apache:solr:3.3
-
cpe:2.3:a:apache:solr:3.3.0
-
cpe:2.3:a:apache:solr:3.4.0
-
cpe:2.3:a:apache:solr:3.5.0
-
cpe:2.3:a:apache:solr:3.6.0
-
cpe:2.3:a:apache:solr:3.6.1
-
cpe:2.3:a:apache:solr:3.6.2
-
cpe:2.3:a:apache:solr:4.0.0
-
cpe:2.3:a:apache:solr:4.1.0
-
cpe:2.3:a:apache:solr:4.10.0
-
cpe:2.3:a:apache:solr:4.10.1
-
cpe:2.3:a:apache:solr:4.10.2
-
cpe:2.3:a:apache:solr:4.10.3
-
cpe:2.3:a:apache:solr:4.10.4
-
cpe:2.3:a:apache:solr:4.2.0
-
cpe:2.3:a:apache:solr:4.2.1
-
cpe:2.3:a:apache:solr:4.3.0
-
cpe:2.3:a:apache:solr:4.3.1
-
cpe:2.3:a:apache:solr:4.4.0
-
cpe:2.3:a:apache:solr:4.5.0
-
cpe:2.3:a:apache:solr:4.5.1
-
cpe:2.3:a:apache:solr:4.6.0
-
cpe:2.3:a:apache:solr:4.6.1
-
cpe:2.3:a:apache:solr:4.7.0
-
cpe:2.3:a:apache:solr:4.7.1
-
cpe:2.3:a:apache:solr:4.7.2
-
cpe:2.3:a:apache:solr:4.8.0
-
cpe:2.3:a:apache:solr:4.8.1
-
cpe:2.3:a:apache:solr:4.9.0
-
cpe:2.3:a:apache:solr:4.9.1
-
cpe:2.3:a:apache:solr:5.0
-
cpe:2.3:a:apache:solr:5.0.0
-
cpe:2.3:a:apache:solr:5.1
-
cpe:2.3:a:apache:solr:5.1.0
-
cpe:2.3:a:apache:solr:5.2.0
-
cpe:2.3:a:apache:solr:5.2.1
-
cpe:2.3:a:apache:solr:5.3
-
cpe:2.3:a:apache:solr:5.3.0
-
cpe:2.3:a:apache:solr:5.3.1
-
cpe:2.3:a:apache:solr:5.3.2
-
cpe:2.3:a:apache:solr:5.4.0
-
cpe:2.3:a:apache:solr:5.4.1
-
cpe:2.3:a:apache:solr:5.5.0
-
cpe:2.3:a:apache:solr:5.5.1
-
cpe:2.3:a:apache:solr:5.5.2
-
cpe:2.3:a:apache:solr:5.5.3
-
cpe:2.3:a:apache:solr:5.5.4
-
cpe:2.3:a:apache:solr:5.5.5
-
cpe:2.3:a:apache:solr:6.0.0
-
cpe:2.3:a:apache:solr:6.0.1
-
cpe:2.3:a:apache:solr:6.1.0
-
cpe:2.3:a:apache:solr:6.2.0
-
cpe:2.3:a:apache:solr:6.2.1
-
cpe:2.3:a:apache:solr:6.3.0
-
cpe:2.3:a:apache:solr:6.4.0
-
cpe:2.3:a:apache:solr:6.4.1
-
cpe:2.3:a:apache:solr:6.4.2
-
cpe:2.3:a:apache:solr:6.5.0
-
cpe:2.3:a:apache:solr:6.5.1
-
cpe:2.3:a:apache:solr:6.6.0
-
cpe:2.3:a:apache:solr:6.6.1
-
cpe:2.3:a:apache:solr:6.6.2
-
cpe:2.3:a:apache:solr:6.6.3
-
cpe:2.3:a:apache:solr:6.6.4
-
cpe:2.3:a:apache:solr:6.6.5
-
cpe:2.3:a:apache:solr:6.6.6
-
cpe:2.3:a:apache:solr:7.0.0
-
cpe:2.3:a:apache:solr:7.0.1
-
cpe:2.3:a:apache:solr:7.1.0
-
cpe:2.3:a:apache:solr:7.2.0
-
cpe:2.3:a:apache:solr:7.2.1
-
cpe:2.3:a:apache:solr:7.3.0
-
cpe:2.3:a:apache:solr:7.3.1
-
cpe:2.3:a:apache:solr:7.4.0
-
cpe:2.3:a:apache:solr:7.5.0
-
cpe:2.3:a:apache:solr:7.6.0