Skip to content
COOEY

EXPOSURES › CVE-2019-17558

CVE-2019-17558

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-17558 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Apache Solr's VelocityResponseWriter plug-in suffered a remote code execution vulnerability that was actively exploited in the wild.

An unspecified vulnerability in the VelocityResponseWriter plug-in allowed remote code execution, and the CVE was added to CISA's KEV catalog, indicating active exploitation. DIB organizations must ensure all optional Solr modules and plug-ins are patched and monitored, as unpatched RCE flaws in search platforms can lead to system compromise and data exfiltration.

Shame score — The vulnerability was actively exploited in the wild and added to CISA's KEV catalog, demonstrating a failure to patch a known, high-severity RCE flaw in a widely deployed open-source search platform.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Apache faced severe fallout due to an RCE vulnerability in Solr, though the provided sources lack specific press commentary or authority condemnation, only technical CVE listings and vendor PSIRT page
cooey ↗ severe-fallout -0.60
Severe vulnerability disclosed, no praise.
"The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution."
fortiguard.fortinet.com ↗ severe-fallout -0.40
Severe vulnerability acknowledged by FortiGuard.
"PSIRT | FortiGuard Labs"
www.cvefind.com ↗ severe-fallout +0.00
Neutral CVE database, no commentary.
NVD ↗ severe-fallout +0.00
Neutral CVE listing, no commentary.
sam.gov ↗ severe-fallout +0.00
Neutral procurement page, no commentary.
github.com ↗ severe-fallout +0.00
Neutral GitHub mirror, no commentary.
app.opencve.io ↗ severe-fallout +0.00
Neutral CVE listing, no commentary.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.