CVE-2015-8795

NameCVE-2015-8795
DescriptionMultiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related to webapp/web/js/scripts/schema-browser.js.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lucene-solr (PTS)jessie3.6.2+dfsg-5fixed
jessie (security)3.6.2+dfsg-5+deb8u2fixed
stretch3.6.2+dfsg-10+deb9u1fixed
stretch (security)3.6.2+dfsg-10+deb9u2fixed
buster, sid3.6.2+dfsg-13fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lucene-solrsource(unstable)(not affected)

Notes

- lucene-solr <not-affected> (Vulnerable code not present)
https://issues.apache.org/jira/browse/SOLR-7346

Search for package or bug name: Reporting problems