ESB-2017.2656 - ALERT [Win][UNIX/Linux] Apache Solr: Execute arbitrary code/commands - Remote/unauthenticated 2017-10-20

Printable version
PGP/GPG verifiable version

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2017.2656
        CVE-2017-12629: Several critical vulnerabilities discovered
                        in Apache Solr (XXE & RCE)
                              20 October 2017

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           Apache Solr
Publisher:         Apache
Operating System:  Windows
                   UNIX variants (UNIX, Linux, OSX)
Impact/Access:     Execute Arbitrary Code/Commands -- Remote/Unauthenticated
                   Access Confidential Data        -- Remote/Unauthenticated
                   Denial of Service               -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2017-12629  

Original Bulletin: 
   https://lucene.apache.org/solr/news.html#12-october-2017-please-secure-your-apache-solr-servers-since-a-zero-day-exploit-has-been-reported-on-a-public-mailing-list

- --------------------------BEGIN INCLUDED TEXT--------------------

CVE-2017-12629: Several critical vulnerabilities discovered in Apache
Solr (XXE & RCE)

Severity: Critical

Vendor:
The Apache Software Foundation

Versions Affected:
Solr 5.5.0 to 5.5.4
Solr 6.0.0 to 6.6.1
Solr 7.0.0 to 7.0.1

Description:
The details of this vulnerability were reported on public mailing
lists. See https://s.apache.org/FJDl

The first vulnerability relates to XML external entity expansion in
the XML Query Parser which is available, by default, for any query
request with parameters deftype=xmlparser. This can be exploited to
upload malicious data to the /upload request handler. It can also be
used as Blind XXE using ftp wrapper in order to read arbitrary local
files from the solr server.

The second vulnerability relates to remote code execution using the
RunExecutableListener available on all affected versions of Solr.

At the time of the above report, this was a 0-day vulnerability with a
working exploit affecting the versions of Solr mentioned in the
previous section. However, mitigation steps were announced to protect
Solr users the same day. See
https://lucene.apache.org/solr/news.html#12-october-2017-please-secure-your-apache-solr-servers-since-a-zero-day-exploit-has-been-reported-on-a-public-mailing-list

Mitigation:
Users are advised to upgrade to either Solr 6.6.2 or Solr 7.1.0
releases both of which address the two vulnerabilities. Once upgrade is
complete, no other steps are required.

If users are unable to upgrade to Solr 6.6.2 or Solr 7.1.0 then they
are advised to restart their Solr instances with the system parameter
`-Ddisable.configEdit=true`. This will disallow any changes to be made
to your configurations via the Config API. This is a key factor in
this vulnerability, since it allows GET requests to add the
RunExecutableListener to your config. Users are also advised to re-map
the XML Query Parser to another parser to mitigate the XXE
vulnerability. For example, adding the following to the solrconfig.xml
file re-maps the xmlparser to the edismax parser:
<queryParser name="xmlparser" class="solr.ExtendedDismaxQParserPlugin"/>

Credit:
Michael Stepankin (JPMorgan Chase)
Olga Barinova (Gotham Digital Science)

References:
https://issues.apache.org/jira/browse/SOLR-11482
https://issues.apache.org/jira/browse/SOLR-11477
https://wiki.apache.org/solr/SolrSecurity

- -- 
Regards,
Shalin Shekhar Mangar.

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBWelJaYx+lLeg9Ub1AQh2/BAAi1PhMFqwDwmknKWINdmhXvu6E1aZoER8
5ZcSXsPxaZNsvVliBnob0HiCL/tVW6sbkxKiW01poRQ6eL0aqWnN4hc/Kr/sol1c
qKcMxPi9K9Au/OaYYUv2wYMuAdewsP75JdSJBQkwj4c8Ft6XH7DpRYKUfsRKaRhU
j4+uDyC+I/MnOaaXea1JiasqRwDXkQbr/uOa6mSOhVt0Eunn+JlmLNohNhv+d2NY
msBa4cC2Wo3vFR33xeV5q91iPU1rVfee0FW5lXdNrODWfs/jXKZRnRyExVBhlhVc
iwfgFPLoM523TBJWJTTs8pPrbxQshRF1Yi5axXve8gvqbHSj/zwd5zKn4Obc0sOq
a8RXpLRR6KPSnYGL/TLfxCK5oVRC5lyDN2dW41K+TFWAMLBfl3jUrIXBCIxPKPad
WjBCI0VBRwZn6DOiSbVmuR8ok6BpRnZ32Avns/jdaV+VQhmmdhU/7j66/b1vSYJw
CYIwQKa295at9Eh5FSkKyIEgtBBPjZF0Hyubjfy6HlSkona/LNsOvxnqIMQKLjTW
L3F/dzjD4uCYCcjTrSWgo83StrckZ4NkheqnYNMD8sMbWAQUHDgVa53wOLRDsWGK
2ajxppz9SPT2Dh04lwZeFOy2PVSvA+p75Kim4YlgOnpNeEEgeVti0pRJ1LshxqPe
/izsTm+P0WQ=
=Udq4
-----END PGP SIGNATURE-----

« Back to bulletins