CVE-2017-3164: Apache Solr
High severity, CVSS 7.5. EPSS: 19.4% chance of exploitation in the next 30 days.
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.
Affected products
- Apache Solr: from 1.3.0, up to and including 7.6.0
Published 2019-03-08. Last modified 2026-06-17.