Re: Fwd: CVE-2017-3163 - SOLR-5.2.1 version

2017-11-20 Thread Rick Leir
Pad Read the CVE. Do you have an affected version of Solr? Do you have the replication feature enabled in solrconfig.xml? Note that it might be enabled by default. Test directory traversal on your system: can you read files remotely? No? Then you are finished. A better plan: upgrade to a newer

Fwd: CVE-2017-3163 - SOLR-5.2.1 version

2017-11-20 Thread padmanabhan gonesani
Please help me here -- Forwarded message -- From: padmanabhan gonesani Date: Mon, Nov 13, 2017 at 5:12 PM Subject: CVE-2017-3163 - SOLR-5.2.1 version To: gene...@lucene.apache.org Hi Team, *Description:* Apache Solr could allow a remote attacker to