GHSA-2289-pqfq-6wx7 · Severity: critical · Ecosystem: maven — Unrestricted upload of file with dangerous type in Apache Solr
The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring will be enabled and exposed on RMI_PORT (default=18983), without any authentication. If this port is opened for inbound traffic in your firewall, then anyone with network access to your Solr nodes will be able to access JMX, which may in turn allow them to upload malicious code for execution on the Solr server.
Conclusion & alert: CVE-2019-12409 is rated High Exploit Risk (88.7/100): CVSS Critical severity, with high exploitation likelihood (EPSS 82.77%, 99th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-26 | 82.99% | 82.77% | -0.22% |
| 2 | 2026-03-21 | 82.77% | 82.99% | +0.22% |
| 3 | 2025-11-21 | — | 82.77% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-2289-pqfq-6wx7 · Severity: critical · Ecosystem: maven — Unrestricted upload of file with dangerous type in Apache Solr
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2019-12409 unimportant priority: Debian including 1 source packages (lucene-solr), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-12409 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2019-12409 |
ubuntu
|
medium | CVE-2019-12409 medium priority: Ubuntu including 1 source packages (lucene-solr), 6 status rows across 6 suites (bionic, disco, eoan, trusty, upstream, xenial): not-affected 5, needs-triage 1. | https://ubuntu.com/security/CVE-2019-12409 |