← Vulnerability feed

Vulnerability record · CVE-2019-17558 · published 30 December 2019

CVE-2019-17558: Apache Solr VelocityResponseWriter template injection enables remote code execution

Apache · Solr

Apache Solr 5.0.0 through 8.3.1 renders Velocity templates through VelocityResponseWriter, and attacker-supplied templates can execute code. Parameter-provided templates are off by default and require a response writer configured with params.resource.loader.enabled=true, which itself requires configuration API access; configset-provided templates are the other path. Solr 8.4 removed the params resource loader and only renders configset templates from trusted configsets.

7.5 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 99% · top 0.1% CWE-74 · Injection
7.5CVSS 3.1 base score, v2 4.6
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
59References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe flaw yields remote code execution in a widely deployed search platform, is in CISA KEV, and has an EPSS probability near 0.99 with public exploit references.

What it is

Apache Solr 5.0.0 through 8.3.1 renders Velocity templates through VelocityResponseWriter, and attacker-supplied templates can execute code. Parameter-provided templates are off by default and require a response writer configured with params.resource.loader.enabled=true, which itself requires configuration API access; configset-provided templates are the other path. Solr 8.4 removed the params resource loader and only renders configset templates from trusted configsets.

Impact

An attacker who can supply a renderable Velocity template gains remote code execution in the Solr process, with high impact to confidentiality, integrity and availability.

Attack surface

Reached over the network via Solr HTTP requests; the CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N). Enabling parameter templates requires configuration API access, so the practical path depends on the attacker already holding some Solr access or on a malicious configset being loaded.

Exploitation

Listed in CISA KEV since 2021-11-03 with a 2022-05-03 remediation due date, and EPSS is very high (0.98567, 99.92nd percentile); references carry Exploit tags, indicating public exploit material exists. No ransomware campaign use is recorded.

What to do

  • Upgrade Apache Solr to 8.4 or later, which removes the params resource loader and restricts configset template rendering to trusted configsets.
  • If upgrade is not immediately possible, ensure no response writer is configured with params.resource.loader.enabled=true and remove or disable VelocityResponseWriter where it is not needed.
  • Restrict access to the Solr configuration API and the Solr HTTP endpoint to trusted networks and authenticated administrative users only.
  • Audit configsets for untrusted or unexpected velocity/ template directories and remove any that are not required.
  • Apply vendor updates for products bundling Solr, such as Oracle Primavera Unifier, per vendor instructions.

Detection

  • Search Solr logs and configuration for response writers or configsets referencing params.resource.loader.enabled or VelocityResponseWriter.
  • Monitor Solr HTTP requests for Velocity template parameters and unusual query or config API calls from unexpected sources.
  • Alert on child processes or outbound network connections spawned by the Solr process, which can indicate template-driven code execution.
  • Review configset uploads and changes for untrusted or newly introduced velocity/ template files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-17558 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/157078/Apache-Solr-8.3.0-Velocity-Template-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
https://issues.apache.org/jira/browse/SOLR-13971 ExploitIssue TrackingPatchVendor Advisory
https://lists.apache.org/thread.html/r0b7b9d4113e6ec1ae1d3d0898c645f758511107ea44f0f3a1210c5d5%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/r12ab2cb15a34e49b4fecb5b2bdd7e10f3e8b7bf1f4f47fcde34d3a7c%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/r19d23e8640236a3058b4d6c23e5cd663fde182255f5a9d63e0606a66%40%3Cdev.lucene.apache.or Mailing List
https://lists.apache.org/thread.html/r1d4a247329a8478073163567bbc8c8cb6b49c6bfc2bf58153a857af1%40%3Ccommits.druid.apache Mailing List
https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apa Mailing List
https://lists.apache.org/thread.html/r25f1bd4545617f5b86dde27b4c30fec73117af65598a30e20209739a%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/r339865b276614661770c909be1dd7e862232e3ef0af98bfd85686b51%40%3Cdev.lucene.apache.or Issue TrackingMailing List
https://lists.apache.org/thread.html/r36e35fd76239a381643555966fb3e72139e018d52d76544fb42f96d8%40%3Cissues.lucene.apache Issue TrackingMailing List
https://lists.apache.org/thread.html/r5074d814d3a8c75df4b20e66bfd268ee0a73ddea7e85070cec3ae78d%40%3Cissues.lucene.apache ExploitMailing List
https://lists.apache.org/thread.html/r58c58fe51c87bc30ee13bb8b4c83587f023edb349018705208e65b37%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/r5dc200f7337093285bac40e6d5de5ea66597c3da343a0f7553f1bb12%40%3Csolr-user.lucene.apa Mailing List
https://lists.apache.org/thread.html/r79c7e75f90e735fd32c4e3e97340625aab66c09dfe8c4dc0ab768b69%40%3Csolr-user.lucene.apa Mailing List
https://lists.apache.org/thread.html/r7b89b3dcfc1b6c52dd8d610b897ac98408245040c92b484fe97a51a2%40%3Csolr-user.lucene.apa Mailing List
https://lists.apache.org/thread.html/r7f21ab40a9b17b1a703db84ac56773fcabacd4cc1eb5c4700d17c071%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/r8a36e4f92f4449dec517e560e1b55639f31b3aca26c37bbad45e31de%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/r8e7a3c253a695a7667da0b0ec57f9bb0e31f039e62afbc00a1d96f7b%40%3Csolr-user.lucene.apa Mailing List
https://lists.apache.org/thread.html/r9271d030452170ba6160c022757e1b5af8a4c9ccf9e04164dec02e7f%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/r99c3f7ec3a079e2abbd540ecdb55a0e2a0f349ca7084273a12e87aeb%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/ra29fa6ede5184385bf2c63e8ec054990a7d4622bba1d244bee70d82d%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/rafc939fdd753f55707841cd5886fc7fcad4d8d8ba0c72429b3220a9a%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/rb964fe5c4e3fc05f75e8f74bf6b885f456b7a7750c36e9a8045c627a%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/rc400db37710ee79378b6c52de3640493ff538c2beb41cefdbbdf2ab8%40%3Ccommits.submarine.ap Mailing List
https://lists.apache.org/thread.html/rde3dbd8e646dabf8bef1b097e9a13ee0ecbdb8441aaed6092726c98d%40%3Cissues.ambari.apache Mailing List
https://lists.apache.org/thread.html/re8d12db916b5582a23ed144b9c5abd0bea0be1649231aa880f6cbfff%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/rf5230a049d989dbfdd404b4320a265dceeeba459a4d04ec21873bd55%40%3Csolr-user.lucene.apa Mailing List
https://lists.apache.org/thread.html/rf6d7ffae2b940114324e036b6394beadf27696d051ae0c4a5edf07af%40%3Cissues.lucene.apache ExploitMailing List
https://www.oracle.com/security-alerts/cpuoct2020.html Third Party Advisory
http://packetstormsecurity.com/files/157078/Apache-Solr-8.3.0-Velocity-Template-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
https://issues.apache.org/jira/browse/SOLR-13971 ExploitIssue TrackingPatchVendor Advisory
https://lists.apache.org/thread.html/r0b7b9d4113e6ec1ae1d3d0898c645f758511107ea44f0f3a1210c5d5%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/r12ab2cb15a34e49b4fecb5b2bdd7e10f3e8b7bf1f4f47fcde34d3a7c%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/r19d23e8640236a3058b4d6c23e5cd663fde182255f5a9d63e0606a66%40%3Cdev.lucene.apache.or Mailing List
https://lists.apache.org/thread.html/r1d4a247329a8478073163567bbc8c8cb6b49c6bfc2bf58153a857af1%40%3Ccommits.druid.apache Mailing List
https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apa Mailing List
https://lists.apache.org/thread.html/r25f1bd4545617f5b86dde27b4c30fec73117af65598a30e20209739a%40%3Cissues.lucene.apache Mailing List
https://lists.apache.org/thread.html/r339865b276614661770c909be1dd7e862232e3ef0af98bfd85686b51%40%3Cdev.lucene.apache.or Issue TrackingMailing List
https://lists.apache.org/thread.html/r36e35fd76239a381643555966fb3e72139e018d52d76544fb42f96d8%40%3Cissues.lucene.apache Issue TrackingMailing List
https://lists.apache.org/thread.html/r5074d814d3a8c75df4b20e66bfd268ee0a73ddea7e85070cec3ae78d%40%3Cissues.lucene.apache ExploitMailing List

Track CVE-2019-17558 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.2CVE-2019-0193Apache Solr DataImportHandler dataConfig parameter code injectionApache Solr's DataImportHandler accepts a full DIH configuration through the request's dataConfig parameter, and because a DIH config can contain scr…KEVEPSS 84%analysed10.0CVE-2018-14721Fasterxml jackson-databind server-side request forgery (ssrf) vulnerabilityFasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure …EPSS 10%9.8CVE-2026-44825Apache solr hard-coded credentials vulnerabilityHardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a …EPSS 2.8%9.8CVE-2024-45216Apache Solr PKIAuthenticationPlugin authentication bypass via fake URL path endingApache Solr instances using the PKIAuthenticationPlugin, enabled by default when Solr Authentication is used, can be bypassed by appending a fake pat…EPSS 93%analysed9.8CVE-2021-44548Apache solr improper input validation vulnerabilityAn Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB n…EPSS 5.1%9.8CVE-2021-23450Linuxfoundation dojo prototype pollution vulnerabilityAll versions of package dojo are vulnerable to Prototype Pollution via the setObject function.EPSS 30%9.8CVE-2021-42575Owasp java html sanitizer vulnerabilityThe OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2019-17558), CISA KEV, FIRST EPSS (scores of 2026-09-18). This page is refreshed as NVD updates the record.