Solr™ News

CVE-2023-50290: Apache Solr allows read access to host environment variables

Security: 12 January 2024

Severity: Important Versions Affected: Solr 9.0 to 9.2.1 Description: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. Users are able to specify which environment variables to hide, however …


Apache Solr™ 9.4.0 available

News: 15 October 2023

The Solr PMC is pleased to announce the release of Apache Solr 9.4.0. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Solr project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 9.3.0 available

News: 21 July 2023

The Solr PMC is pleased to announce the release of Apache Solr 9.3.0. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Solr project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 9.2.1 available

News: 1 May 2023

The Solr PMC is pleased to announce the release of Apache Solr 9.2.1. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Solr project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 9.2.0 available

News: 24 March 2023

The Solr PMC is pleased to announce the release of Apache Solr 9.2.0. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Solr project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 9.1.1 available

News: 25 January 2023

The Solr PMC is pleased to announce the release of Apache Solr 9.1.1. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Solr project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr is vulnerable to CVE-2022-39135 via /sql handler

Security: 20 November 2022

Versions Affected: Solr 6.5 to 8.11.2 Solr 9.0 Description: Apache Calcite has a vulnerability, CVE-2022-39135, that is exploitable in Apache Solr in SolrCloud mode. If an untrusted user can supply SQL queries to Solr’s “/sql” handler (even indirectly via proxies / other apps), then the user …


Apache Solr™ 9.1.0 available

News: 17 November 2022

The Solr PMC is pleased to announce the release of Apache Solr 9.1.0. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Solr project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Java 17 bug affecting Solr

News: 21 October 2022

Several users running Solr in production on OpenJDK 17 have experienced JVM crashes due to a known bug in the JDK. Read more about the bug in SOLR-16463. Known mitigations are to either downgrade to JDK 11 or to start Solr with a Java startup flag that avoids the failure …


Solr 8 Docker image changes to Eclipse Temurin JDK

News: 20 October 2022

The official docker image for Solr 8.11 has been running on Oracle OpenJDK 11 JRE. However, due to Oracle's new release policies, they now no longer provide support for JDK11. Since Solr 8.11 is still being supported by the Apache Solr project, we needed to switch to another …


Solr Docker images now pin the Linux release

News: 20 October 2022

Solr 9 was released on May 12th, using the eclipse-temurin:17-jre base image. Thus, we are pinned to Java 17 and Solr's Docker image will thus always use an updated Java 17 version. If you pull the docker image from time to time that is. However, the base image tag …


Apache Solr™ 8.11.2 available

News: 17 June 2022

The Lucene and Solr PMCs are pleased to announce the release of Apache Solr 8.11.2. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document …


Apache Solr™ 9.0.0 available

News: 12 May 2022

The Solr PMC is pleased to announce the release of Apache Solr 9.0.0. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Solr project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


CVE-2021-44548: Apache Solr information disclosure vulnerability through DataImportHandler

Security: 18 December 2021

Severity: Moderate Versions Affected: All versions prior to 8.11.1. Affected platforms: Windows. Description: An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB network call being made from the Solr host to another host on …


Apache Solr™ 8.11.1 available

News: 16 December 2021

The Lucene PMC is pleased to announce the release of Apache Solr 8.11.1. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr affected by Apache Log4J CVE-2021-44228

Security: 10 December 2021

Severity: Critical Versions Affected: 7.4.0 to 7.7.3, 8.0.0 to 8.11.0 Description: Apache Solr releases prior to 8.11.1 were using a bundled version of the Apache Log4J library vulnerable to RCE. For full impact and additional detail consult the Log4J security …


Apache Solr™ 8.11.0 available

News: 16 November 2021

The Solr PMC is pleased to announce the release of Apache Solr 8.11.0. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 8.10.1 available

News: 18 October 2021

The Solr PMC is pleased to announce the release of Apache Solr 8.10.1. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 8.10.0 available

News: 27 September 2021

The Solr PMC is pleased to announce the release of Apache Solr 8.10.0. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 8.9.0 available

News: 16 June 2021

The Solr PMC is pleased to announce the release of Apache Solr 8.9.0. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …