Solr™ News

Apache Solr™ 8.8.2 available

News: 12 April 2021

The Solr PMC is pleased to announce the release of Apache Solr 8.8.2. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


CVE-2021-27905: SSRF vulnerability with the Replication handler

Security: 12 April 2021

Severity: High Versions Affected: 7.0.0 to 7.7.3 8.0.0 to 8.8.1 Description: The ReplicationHandler (normally registered at "/replication" under a Solr core) has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index …


CVE-2021-29262: Misapplied Zookeeper ACLs can result in leakage of configured authentication and authorization settings

Security: 12 April 2021

Severity: High Versions Affected: 7.0.0 to 7.7.3 8.0.0 to 8.8.1 Description: When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr …


CVE-2021-29943: Apache Solr Unprivileged users may be able to perform unauthorized read/write to collections

Security: 12 April 2021

Severity: High Versions Affected: 7.0.0 to 7.7.3 8.0.0 to 8.8.1 Description: When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect …


Apache Solr™ 8.8.1 available

News: 22 February 2021

The Lucene PMC is pleased to announce the release of Apache Solr 8.8.1. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr becomes an Apache TLP

News: 17 February 2021

The Apache Software Foundation's board today established Solr as a Top Level Project (TLP). Solr has been a Lucene sub-project since its incubation in 2006, governed by the Lucene PMC, and has since the 3.1 release also shared source code repository with Lucene. What's the background? The change was …


Apache Solr™ 8.8.0 available

News: 29 January 2021

29/01/2021, Apache Solr™ 8.8 available The Lucene PMC is pleased to announce the release of Apache Solr 8.8 Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search and …


Apache Solr™ 8.7.0 available

News: 3 November 2020

3/11/2020, Apache Solr™ 8.7 available The Lucene PMC is pleased to announce the release of Apache Solr 8.7 Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search and …


CVE-2020-13957: The checks added to unauthenticated configset uploads in Apache Solr can be circumvented

Security: 12 October 2020

Severity: High Versions Affected: 6.6.0 to 6.6.6 7.0.0 to 7.7.3 8.0.0 to 8.6.2 Description: Solr prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API …


Apache Solr™ 8.6.3 available

News: 7 October 2020

The Lucene PMC is pleased to announce the release of Apache Solr 8.6.3. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 8.6.2 available

News: 1 September 2020

The Lucene PMC is pleased to announce the release of Apache Solr 8.6.2. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


CVE-2020-13941: Apache Solr information disclosure vulnerability

Security: 14 August 2020

Severity: Medium Versions Affected: Before Solr 8.6. Some risks are specific to Windows. Description: Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://solr.apache.org/guide/8_6/index-replication.html#http-api-commands-for-the-replicationhandler) allows commands backup, restore and deleteBackup. Each …


Apache Solr™ 8.6.1 available

News: 13 August 2020

The Lucene PMC is pleased to announce the release of Apache Solr 8.6.1. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 8.6.0 available

News: 15 July 2020

The Lucene PMC is pleased to announce the release of Apache Solr 8.6.0. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 8.5.2 available

News: 26 May 2020

The Lucene PMC is pleased to announce the release of Apache Solr 8.5.2. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 7.7.3 available

News: 28 April 2020

The Lucene PMC is pleased to announce the release of Apache Solr 7.7.3. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 8.5.1 available

News: 16 April 2020

The Lucene PMC is pleased to announce the release of Apache Solr 8.5.1 Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search and analytics, rich document parsing, geospatial search, extensive …


Apache Solr™ 8.5.0 available

News: 24 March 2020

The Lucene PMC is pleased to announce the release of Apache Solr 8.5.0. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 8.4.1 available

News: 13 January 2020

The Lucene PMC is pleased to announce the release of Apache Solr 8.4.1. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


CVE-2019-17558: Apache Solr RCE through VelocityResponseWriter

Security: 30 December 2019

Severity: High Vendor: The Apache Software Foundation Versions Affected: 5.0.0 to 8.3.1 Description: The affected versions are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset velocity/ directory or as a parameter. A user …