← back
CVE-2017-3164

CVE-2017-3164

EPSS 19.4%
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 19.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
08 Mar 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →