peter bassill · operator
$ cve CVE-2020-13957 JSON

CVE-2020-13957

9.8
CRITICAL · CVSS 3.1 · EPSS 79.3% (pctl 100)

Patch early

EPSS 79.3% — above the 10% action threshold.

Description

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS79.34% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-863
On CISA KEVno
Public exploitnone known
Published2020-10-13
Last modified2026-06-17

Affected (1)

VendorProduct
apachesolr

References

→ the Explorer  ·  watch your stack  ·  NVD