Vulnerability record · CVE-2019-17558 · published 30 December 2019
CVE-2019-17558: Apache Solr VelocityResponseWriter template injection enables remote code execution
Apache · Solr
Apache Solr 5.0.0 through 8.3.1 renders Velocity templates through VelocityResponseWriter, and attacker-supplied templates can execute code. Parameter-provided templates are off by default and require a response writer configured with params.resource.loader.enabled=true, which itself requires configuration API access; configset-provided templates are the other path. Solr 8.4 removed the params resource loader and only renders configset templates from trusted configsets.
Description
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw yields remote code execution in a widely deployed search platform, is in CISA KEV, and has an EPSS probability near 0.99 with public exploit references.
What it is
Apache Solr 5.0.0 through 8.3.1 renders Velocity templates through VelocityResponseWriter, and attacker-supplied templates can execute code. Parameter-provided templates are off by default and require a response writer configured with params.resource.loader.enabled=true, which itself requires configuration API access; configset-provided templates are the other path. Solr 8.4 removed the params resource loader and only renders configset templates from trusted configsets.
Impact
An attacker who can supply a renderable Velocity template gains remote code execution in the Solr process, with high impact to confidentiality, integrity and availability.
Attack surface
Reached over the network via Solr HTTP requests; the CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N). Enabling parameter templates requires configuration API access, so the practical path depends on the attacker already holding some Solr access or on a malicious configset being loaded.
Exploitation
Listed in CISA KEV since 2021-11-03 with a 2022-05-03 remediation due date, and EPSS is very high (0.98567, 99.92nd percentile); references carry Exploit tags, indicating public exploit material exists. No ransomware campaign use is recorded.
What to do
- Upgrade Apache Solr to 8.4 or later, which removes the params resource loader and restricts configset template rendering to trusted configsets.
- If upgrade is not immediately possible, ensure no response writer is configured with params.resource.loader.enabled=true and remove or disable VelocityResponseWriter where it is not needed.
- Restrict access to the Solr configuration API and the Solr HTTP endpoint to trusted networks and authenticated administrative users only.
- Audit configsets for untrusted or unexpected velocity/ template directories and remove any that are not required.
- Apply vendor updates for products bundling Solr, such as Oracle Primavera Unifier, per vendor instructions.
Detection
- Search Solr logs and configuration for response writers or configsets referencing params.resource.loader.enabled or VelocityResponseWriter.
- Monitor Solr HTTP requests for Velocity template parameters and unusual query or config API calls from unexpected sources.
- Alert on child processes or outbound network connections spawned by the Solr process, which can indicate template-driven code execution.
- Review configset uploads and changes for untrusted or newly introduced velocity/ template files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-17558 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-17558 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-17558), CISA KEV, FIRST EPSS (scores of 2026-09-18). This page is refreshed as NVD updates the record.