{"id":9565,"date":"2019-11-12T01:43:56","date_gmt":"2019-11-12T01:43:56","guid":{"rendered":"https:\/\/nsfocusglobal.com\/?p=9565"},"modified":"2026-04-17T18:07:51","modified_gmt":"2026-04-17T18:07:51","slug":"apache-solr-velocity-remote-code-execution-vulnerability-handling-guide","status":"publish","type":"post","link":"https:\/\/nsfocusglobal.com\/pt-br\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/","title":{"rendered":"Apache Solr velocity Remote Code Execution Vulnerability Handling Guide"},"content":{"rendered":"<p><!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\"><br \/>\n<html><body><\/p>\n<h2><strong>Vulnerability Description<\/strong><\/h2>\n<p>On October 30, @_S00pY disclosed the exploitation of Apache Solr Remote Code Execution Vulnerability, which allows attackers to implement remote code execution via velocity templates. After testing, the vulnerability can be successfully triggered, and no official security patch has been released.<!--more--><\/p>\n<p>This vulnerability needs to be triggered in two steps. First, the attacker needs to modify the &#8220;params.Resource.Loader.Enabled&#8221; configuration item to True through the config API, and then complete the vulnerability trigger by sending a malicious velocity template.<\/p>\n<p>Some POC codes are as follows:<\/p>\n<p><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-1.jpg\"><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone size-full wp-image-9566\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-1.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" width=\"567\" height=\"224\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-1.jpg 567w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-1-300x119.jpg 300w\" sizes=\"(max-width: 567px) 100vw, 567px\" \/><\/a><\/p>\n<p>After successful utilization, arbitrary commands can be executed on the server.<\/p>\n<p><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-2.jpg\"><img decoding=\"async\" class=\"alignnone size-full wp-image-9567\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-2.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" width=\"567\" height=\"320\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-2.jpg 567w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-2-300x169.jpg 300w\" sizes=\"(max-width: 567px) 100vw, 567px\" \/><\/a><\/p>\n<h2><strong>Scope of Impact<\/strong><\/h2>\n<p><strong>Affected Versions<\/strong><\/p>\n<ul>\n<li>Apache Solr &lt;= 8.2.0 (versions with config API may be affected by this vulnerability)<\/li>\n<\/ul>\n<h2><strong>Vulnerability Detection<\/strong><\/h2>\n<ul>\n<li>\n<h3><strong>Manual Test<\/strong><\/h3>\n<\/li>\n<\/ul>\n<p>If any of the following conditions are met, the current system may be affected by this vulnerability.<\/p>\n<ol>\n<li>Access http:\/ \/hostname \/Solr\/nstance name \/config and find that the config API is open.<\/li>\n<li>A configfollay.json file exists in the instance configuration directory, under which the configuration item &#8220;params.Resource.Loader.Enabled&#8221;:&#8221;true&#8221; can be found. By default, there is no configfollay.json file.<\/li>\n<\/ol>\n<p><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-3.jpg\"><img decoding=\"async\" class=\"alignnone size-full wp-image-9568\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-3.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" width=\"567\" height=\"325\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-3.jpg 567w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-3-300x172.jpg 300w\" sizes=\"(max-width: 567px) 100vw, 567px\" \/><\/a><\/p>\n<ol start=\"3\">\n<li>In the global configuration file solrconfig.xml, the configuration item &#8220;params.resource.loader.enabled&#8221; is &#8220;true&#8221;.<\/li>\n<\/ol>\n<p><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-4.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-9569\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-4.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" width=\"567\" height=\"354\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-4.jpg 567w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-4-300x187.jpg 300w\" sizes=\"(max-width: 567px) 100vw, 567px\" \/><\/a><\/p>\n<h2><strong>Vulnerability Mitigation<\/strong><\/h2>\n<ul>\n<li>\n<h3><strong>Product Protection<\/strong><\/h3>\n<\/li>\n<\/ul>\n<p>Users deployed with NIPS can protect against this vulnerability by using protection rule 23982.<\/p>\n<p><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-5.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-9570\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-5.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" width=\"567\" height=\"206\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-5.jpg 567w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-5-300x109.jpg 300w\" sizes=\"(max-width: 567px) 100vw, 567px\" \/><\/a><\/p>\n<ul>\n<li><strong>Workaround<\/strong><\/li>\n<\/ul>\n<ol>\n<li>Users can disable access to \/ Solr \/ instance name \/ config by access control.<\/li>\n<li>If &#8221; params.resource.loader.enabled:&acirc;&euro;true&acirc;&euro; exists in the configloverlay.json configuration file, change &acirc;&euro;&oelig;true&acirc;&euro; to &acirc;&euro;&oelig;false&acirc;&euro;.<\/li>\n<\/ol>\n<p><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-6.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-9571\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-6.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" width=\"567\" height=\"174\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-6.jpg 567w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-6-300x92.jpg 300w\" sizes=\"(max-width: 567px) 100vw, 567px\" \/><\/a><\/p>\n<ol start=\"3\">\n<li>If the following configuration &lt;bool name=&#8221;params.resource.loader.enabled&#8221;&gt;true&lt;\/bool&gt; exists in the velocityresponsewriter in the solrconfig.xml configuration file, modify it to &acirc;&euro;&oelig;false&acirc;&euro;.<\/li>\n<\/ol>\n<p><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-7.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-9572\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-7.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" width=\"567\" height=\"255\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-7.jpg 567w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-7-300x135.jpg 300w\" sizes=\"(max-width: 567px) 100vw, 567px\" \/><\/a><\/p>\n<ol start=\"4\">\n<li>Add security authentication. For detailed configuration methods, please refer to the document released by Apache:<\/li>\n<\/ol>\n<p>http:\/\/lucene.apache.org\/solr\/guide\/8_2\/basic-authentication-plugin.html#basic-authentication-plugin<\/p>\n<h2><strong>Statement<\/strong><\/h2>\n<p>This advisory is only used to describe a potential risk. NSFOCUS does not provide any commitment or promise on this advisory. NSFOCUS and the author will not bear any liability for any direct and\/or indirect consequences and losses caused by transmitting and\/or using this advisory. NSFOCUS reserves all the rights to modify and interpret this advisory. Please include this statement paragraph when reproducing or transferring this advisory. Do not modify this advisory, add\/delete any information to\/from it, or use this advisory for commercial purposes without permission from NSFOCUS.<\/p>\n<h2><strong>About NSFOCUS<\/strong><\/h2>\n<p>NSFOCUS, Inc., a global network and cyber security leader, protects enterprises and carriers from advanced cyber attacks. The company&#8217;s Intelligent Hybrid Security strategy utilizes both cloud and on-premises security platforms, built on a foundation of real-time global threat intelligence, to provide multi-layered, unified and dynamic protection against advanced cyber attacks.<\/p>\n<p>NSFOCUS works with Fortune Global 500 companies, including four of the world&#8217;s five largest financial institutions, organizations in insurance, retail, healthcare, critical infrastructure industries as well as government agencies. NSFOCUS has technology and channel partners in more than 60 countries, is a member of both the Microsoft Active Protections Program (MAPP), and the Cloud Security Alliance (CSA).<\/p>\n<p>A wholly owned subsidiary of NSFOCUS Information Technology Co. Ltd., the company has operations in the Americas, Europe, the Middle East and Asia Pacific.<\/p>\n<p>&nbsp;<\/body><\/html><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Vulnerability Description On October 30, @_S00pY disclosed the exploitation of Apache Solr Remote Code Execution Vulnerability, which allows attackers to implement remote code execution via velocity templates. After testing, the vulnerability can be successfully triggered, and no official security patch has been released.<\/p>\n","protected":false},"author":1,"featured_media":9573,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","footnotes":""},"categories":[6],"tags":[72],"class_list":["post-9565","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-emergency-response","tag-apache"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Apache Solr velocity Remote Code Execution Vulnerability Handling Guide - NSFOCUS<\/title>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apache Solr velocity Remote Code Execution Vulnerability Handling Guide - NSFOCUS\" \/>\n<meta property=\"og:description\" content=\"Vulnerability Description On October 30, @_S00pY disclosed the exploitation of Apache Solr Remote Code Execution Vulnerability, which allows attackers to\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/\" \/>\n<meta property=\"og:site_name\" content=\"NSFOCUS\" \/>\n<meta property=\"article:published_time\" content=\"2019-11-12T01:43:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-17T18:07:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-8.jpg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Apache Solr velocity Remote Code Execution Vulnerability Handling Guide - NSFOCUS\" \/>\n<meta name=\"twitter:description\" content=\"Vulnerability Description On October 30, @_S00pY disclosed the exploitation of Apache Solr Remote Code Execution Vulnerability, which allows attackers to\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-8.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. tempo de leitura\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\\\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/person\\\/fd9ab61c9c77a81bbd870f725cc0c61d\"},\"headline\":\"Apache Solr velocity Remote Code Execution Vulnerability Handling Guide\",\"datePublished\":\"2019-11-12T01:43:56+00:00\",\"dateModified\":\"2026-04-17T18:07:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\\\/\"},\"wordCount\":557,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/1112-8.jpg\",\"keywords\":[\"Apache\"],\"articleSection\":[\"Emergency Response\"],\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\\\/\",\"name\":\"Apache Solr velocity Remote Code Execution Vulnerability Handling Guide - NSFOCUS\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/1112-8.jpg\",\"datePublished\":\"2019-11-12T01:43:56+00:00\",\"dateModified\":\"2026-04-17T18:07:51+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\\\/#breadcrumb\"},\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\\\/#primaryimage\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/1112-8.jpg\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/1112-8.jpg\",\"width\":430,\"height\":212,\"caption\":\"Apache Solr logo with red sunburst design.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nsfocusglobal.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apache Solr velocity Remote Code Execution Vulnerability Handling Guide\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#website\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/\",\"name\":\"NSFOCUS\",\"description\":\"Security Made Smart and Simple\",\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pt-BR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#organization\",\"name\":\"NSFOCUS\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"width\":248,\"height\":36,\"caption\":\"NSFOCUS\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/person\\\/fd9ab61c9c77a81bbd870f725cc0c61d\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\\\/\\\/nsfocusglobal.com\"],\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Apache Solr velocity Remote Code Execution Vulnerability Handling Guide - NSFOCUS","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"pt_BR","og_type":"article","og_title":"Apache Solr velocity Remote Code Execution Vulnerability Handling Guide - NSFOCUS","og_description":"Vulnerability Description On October 30, @_S00pY disclosed the exploitation of Apache Solr Remote Code Execution Vulnerability, which allows attackers to","og_url":"https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/","og_site_name":"NSFOCUS","article_published_time":"2019-11-12T01:43:56+00:00","article_modified_time":"2026-04-17T18:07:51+00:00","og_image":[{"url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-8.jpg","type":"","width":"","height":""}],"author":"admin","twitter_card":"summary_large_image","twitter_title":"Apache Solr velocity Remote Code Execution Vulnerability Handling Guide - NSFOCUS","twitter_description":"Vulnerability Description On October 30, @_S00pY disclosed the exploitation of Apache Solr Remote Code Execution Vulnerability, which allows attackers to","twitter_image":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-8.jpg","twitter_misc":{"Escrito por":"admin","Est. tempo de leitura":"3 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/#article","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/"},"author":{"name":"admin","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/person\/fd9ab61c9c77a81bbd870f725cc0c61d"},"headline":"Apache Solr velocity Remote Code Execution Vulnerability Handling Guide","datePublished":"2019-11-12T01:43:56+00:00","dateModified":"2026-04-17T18:07:51+00:00","mainEntityOfPage":{"@id":"https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/"},"wordCount":557,"commentCount":0,"publisher":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#organization"},"image":{"@id":"https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-8.jpg","keywords":["Apache"],"articleSection":["Emergency Response"],"inLanguage":"pt-BR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/","url":"https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/","name":"Apache Solr velocity Remote Code Execution Vulnerability Handling Guide - NSFOCUS","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/#primaryimage"},"image":{"@id":"https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-8.jpg","datePublished":"2019-11-12T01:43:56+00:00","dateModified":"2026-04-17T18:07:51+00:00","breadcrumb":{"@id":"https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/"]}]},{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/#primaryimage","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-8.jpg","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2019\/11\/1112-8.jpg","width":430,"height":212,"caption":"Apache Solr logo with red sunburst design."},{"@type":"BreadcrumbList","@id":"https:\/\/nsfocusglobal.com\/apache-solr-velocity-remote-code-execution-vulnerability-handling-guide\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nsfocusglobal.com\/"},{"@type":"ListItem","position":2,"name":"Apache Solr velocity Remote Code Execution Vulnerability Handling Guide"}]},{"@type":"WebSite","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#website","url":"https:\/\/nsfocusglobal.com\/pt-br\/","name":"NSFOCUS","description":"Security Made Smart and Simple","publisher":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nsfocusglobal.com\/pt-br\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-BR"},{"@type":"Organization","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#organization","name":"NSFOCUS","url":"https:\/\/nsfocusglobal.com\/pt-br\/","logo":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/logo\/image\/","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","width":248,"height":36,"caption":"NSFOCUS"},"image":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/person\/fd9ab61c9c77a81bbd870f725cc0c61d","name":"admin","image":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","caption":"admin"},"sameAs":["https:\/\/nsfocusglobal.com"],"url":"https:\/\/nsfocusglobal.com\/pt-br\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/9565","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/comments?post=9565"}],"version-history":[{"count":0,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/9565\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media\/9573"}],"wp:attachment":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media?parent=9565"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/categories?post=9565"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/tags?post=9565"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}