Bug 1179795 (CVE-2014-3628) - CVE-2014-3628 solr: Cross-site scripting (XSS) vulnerability via the fieldvaluecache object
Summary: CVE-2014-3628 solr: Cross-site scripting (XSS) vulnerability via the fieldval...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2014-3628
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1179814
TreeView+ depends on / blocked
 
Reported: 2015-01-07 15:08 UTC by Vasyl Kaigorodov
Modified: 2019-09-29 13:26 UTC (History)
3 users (show)

Fixed In Version: Apache Solr 4.10.3
Clone Of:
Environment:
Last Closed: 2015-01-12 20:36:29 UTC
Embargoed:


Attachments (Terms of Use)

Description Vasyl Kaigorodov 2015-01-07 15:08:18 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-3628 to
the following vulnerability:

Name: CVE-2014-3628
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3628
Assigned: 20140514
Reference: http://secunia.com/advisories/62024

Cross-site scripting (XSS) vulnerability in the Admin UI Plugin /
Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to
inject arbitrary web script or HTML via the fieldvaluecache object.

Comment 1 gil cattaneo 2015-01-07 15:17:05 UTC
Solr 4.10.3 will be updated soon, are waiting to be able to fill. because requires Lucene 4.10.3. I do not know if it will be possible to upgrade it for F21 since Lucene is a dependency of eclipse.
Close this bug

Comment 2 Vasyl Kaigorodov 2015-01-07 15:31:02 UTC
(In reply to gil cattaneo from comment #1)
> Solr 4.10.3 will be updated soon, are waiting to be able to fill. because
> requires Lucene 4.10.3. I do not know if it will be possible to upgrade it
> for F21 since Lucene is a dependency of eclipse.
> Close this bug

Thanks for the comment, marked Fedora versions as "notaffected".
This bug should be opened though, Solr is shipped in other Red Hat products and we need to check if these are affected or not.
Please don't close this bug.


Note You need to log in before you can comment on or make changes to this bug.