GHSA-rc9v-h28f-jcmf · Severity: medium · Ecosystem: maven — There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. Users are advised to upgrade to either Solr 6.6.4 or Solr 7.3.1 releases both of which address the vulnerability. Once upgrade is complete, no other steps are required. Those releases only allow external entities and Xincludes that refer to local files / zookeeper resources below the Solr instance directory (using Solr's ResourceLoader); usage of absolute URLs is denied. Keep in mind, that external entities and XInclude are explicitly supported to better structure config files in large installations. Before Solr 6 this was no problem, as config files were not accessible through the APIs.
Conclusion & alert: CVE-2018-8010 is rated Moderate Risk (55.3/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 3.92%). Core evidence: EPSS rose +2.21% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.71% | 3.92% | +2.21% |
| 2 | 2026-01-06 | 1.58% | 1.71% | +0.12% |
| 3 | 2026-01-04 | — | 1.58% | — |
Full EPSS history (26 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.5 | 3.0 | MEDIUM |
|
1.8 | 3.6 | [email protected] |
| 2.1 | 2.0 | LOW |
|
3.9 | 2.9 | [email protected] |
GHSA-rc9v-h28f-jcmf · Severity: medium · Ecosystem: maven — There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2018-8010 unimportant priority: Debian including 1 source packages (lucene-solr), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2018-8010 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2018-8010 |
ubuntu
|
medium | CVE-2018-8010 medium priority: Ubuntu including 1 source packages (lucene-solr), 5 status rows across 5 suites (artful, bionic, trusty, upstream, xenial): not-affected 4, needs-triage 1. | https://ubuntu.com/security/CVE-2018-8010 |
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/104239 | Third Party Advisory VDB Entry |
| https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E | |
| https://mail-archives.apache.org/mod_mbox/www-announce/201805.mbox/%3C08a801d3f0f9%24df46d300%249dd47900%24%40apache.org%3E | Mailing List Mitigation Vendor Advisory |