CVE-2019-0193
Apache Solr DataImportHandler Code Injection Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 7.2
- EPSS
- 83.5% 백분위 99.6% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.06.10
- 공개일
- 2019.08.01
CISA KEV에 등록된 실제 악용 확인 취약점
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.
공급사 Apache
제품 Solr
영향 버전 Apache Solr all prior to 8.2.0, < 7.7.3, >= 8.1.0 < 8.1.2, 8.0, 9.0
수정 버전 7.7.3, 8.1.2
Apply updates per vendor instructions.
조치 기한: 2022.06.10CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE CWE-94
KEV 등록일 2021.12.10
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://nvd.nist.gov/vuln/detail/CVE-2019-0193
EPSS 데이터 기준일 2026.06.27