CVE-2017-12629 affects Apache Solr releases before 7.1 and Apache Lucene releases before 7.1. The XML Query Parser permits XML external entity expansion, and Solr's Config API can be abused to add a RunExecutableListener configuration. An unauthenticated remote attacker can manipulate attacker-supplied objects through subsequent requests to construct an executable listener and run arbitrary code. The XXE portion can additionally support blind external-entity attacks and local-file disclosure in affected XML Query Parser deployments. Elasticsearch is not affected merely by its use of Lucene.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a proof-of-concept exploit (rce.py) for CVE-2017-12629, a remote code execution vulnerability in Apache Solr before version 7.1. The exploit leverages an XXE vulnerability in the XML Query Parser, combined with the ability to add a RunExecutableListener via the Config API, to achieve arbitrary command execution on the Solr server. The exploit script is written in Python and provides an interactive shell-like interface, allowing the attacker to execute arbitrary shell commands on the target. Command output is exfiltrated out-of-band using attacker-specified methods (HTTP, DNS, FTP, etc.), with support for hex and base32 encoding. The README provides detailed usage instructions and context. The repository consists of two files: a README.md and the main exploit script rce.py. The exploit is operational and requires the attacker to specify both internal and external Solr URLs, as well as an exfiltration endpoint.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A code-execution vulnerability in Solr caused by entity expansion.
Unauthenticated arbitrary code-execution vulnerability involving Apache Lucene/Solr object handling when Solr's Config API is enabled.
Unauthenticated arbitrary-code-execution flaw involving Apache Lucene/Solr object handling, exploitable when the Apache Solr Config API is enabled.
Unauthenticated object manipulation flaw affecting Apache Lucene/Solr deployments that can enable arbitrary code execution when the Solr Config API is enabled.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.