CVE-2021-27905 is a critical Server-Side Request Forgery (SSRF) vulnerability affecting Apache Solr versions prior to 8.8.2. The vulnerability arises from insufficient validation of the "masterUrl" parameter within the ReplicationHandler, allowing an attacker to force the Solr instance to make requests to arbitrary URLs. This flaw carries a CVSS score of 9.8 (CRITICAL), indicating a network-based attack with low complexity, requiring no user interaction, and leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, exploit templates exist for tools like Nuclei, suggesting readily available proof-of-concept code, though there is no evidence of widespread active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.8.2CPE matchmatch criteria | cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.