CyberSec.Space Logo
Back to CVE Browser

CVE-2019-0193

Known Exploited (CISA KEV)HIGH
7.2
CVSS Severity Score
EPSS Score92.2880%
EPSS Percentile88.37th
PublishedAug 1, 2019
Last ModifiedOct 27, 2025

Vulnerability Description

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.

Affected Platforms (CPE)

πŸ“¦
Apache

Solr

< 7.7.3
πŸ“¦
Apache

Solr

>= 8.1.0 and < 8.1.2
πŸ’»
Debian

Debian Linux

= 8.0
πŸ’»
Debian

Debian Linux

= 9.0

References & Advisories

Related Vulnerabilities