CVE-2017-3164: Apache Solr

High severity, CVSS 7.5. EPSS: 19.4% chance of exploitation in the next 30 days.

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.

Affected products

  • Apache Solr: from 1.3.0, up to and including 7.6.0

Published 2019-03-08. Last modified 2026-06-17.