LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-17558: Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-17558 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.

CVE-2019-17558 is a remote code execution vulnerability in the VelocityResponseWriter plug-in of Apache Solr. It stems from an injection weakness that can let an attacker run code on the Solr host if the plug-in is reachable and misused. For teams running search or indexing infrastructure, this matters because Solr often sits close to sensitive data and internal services; successful abuse can give an attacker a foothold on the application server.

Public detail on exact mechanics is limited beyond the CISA summary and the CWE classification. Confirm affected releases, fixed versions, and configuration prerequisites directly against the vendor advisory before acting.

How it works

The weakness is classified as CWE-74: improper neutralization of special elements in output used by a downstream component (injection). In this case the component is Apache Solr’s VelocityResponseWriter plug-in. Velocity is a templating engine; when user-controlled or attacker-supplied input is incorporated into templates or response-writing paths without adequate sanitization or sandboxing, the engine can be steered into executing unintended logic.

An attacker who can reach the vulnerable response-writer endpoint or configuration surface may supply crafted input that the plug-in processes in a way that leads to remote code execution on the Solr process. The CISA summary describes the issue only as an unspecified vulnerability in the plug-in that can allow remote code execution; no further exploit steps, payloads, or preconditions are provided here. Treat any public proof-of-concept material with caution and validate behavior only in isolated lab environments against the vendor’s own description.

Am I affected? How to find it in your systems

Apache Solr is commonly deployed as a standalone search server, embedded in applications, or run inside containers and orchestration platforms for full-text search, analytics, and log indexing. It may appear in development, staging, and production estates, sometimes exposed only on internal networks.

How to remediate

Patch first. Apply the updates published by the Apache Solr project for this vulnerability exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls.

If your data may have been exposed

Actively exploited remote code execution flaws can lead to host compromise and data access even when ransomware use is not documented for this CVE. If you have reason to believe an instance was reachable and unpatched during the vulnerable period, treat the host as potentially compromised: isolate it, preserve logs and memory images if investigating, rotate credentials and secrets that Solr could access, and review downstream systems for lateral movement. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApache · Solr
WeaknessCWE-74
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities