CVE-2019-0193: Apache Solr DataImportHandler Code Injection Vulnerability

High severity, CVSS 7.2. Actively exploited: in CISA KEV since 2021-12-10. EPSS: 83.5% chance of exploitation in the next 30 days.

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.

Affected products

  • Apache Solr: before 7.7.3 (fixed in 7.7.3); from 8.1.0, before 8.1.2 (fixed in 8.1.2)
  • Debian Debian Linux: version 8.0 only; version 9.0 only

Published 2019-08-01. Last modified 2026-06-17.