EXPOSURES › CVE-2019-17558
CVE-2019-17558
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Solr's VelocityResponseWriter plug-in suffered a remote code execution vulnerability that was actively exploited in the wild.
An unspecified vulnerability in the VelocityResponseWriter plug-in allowed remote code execution, and the CVE was added to CISA's KEV catalog, indicating active exploitation. DIB organizations must ensure all optional Solr modules and plug-ins are patched and monitored, as unpatched RCE flaws in search platforms can lead to system compromise and data exfiltration.
Shame score — The vulnerability was actively exploited in the wild and added to CISA's KEV catalog, demonstrating a failure to patch a known, high-severity RCE flaw in a widely deployed open-source search platform.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
"The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution."
"PSIRT | FortiGuard Labs"