Solr™ News

Apache Solr™ 8.4.0 available

News: 29 December 2019

The Lucene PMC is pleased to announce the release of Apache Solr 8.4.0. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 8.3.1 available

News: 3 December 2019

The Lucene PMC is pleased to announce the release of Apache Solr 8.3.1. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


CVE-2019-12409: Apache Solr RCE vulnerability due to bad config default

Security: 18 November 2019

Severity: High Vendor: The Apache Software Foundation Versions Affected: Solr 8.1.1 and 8.2.0 for Linux Description: The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping …


Apache Solr™ 8.3.0 available

News: 2 November 2019

The Lucene PMC is pleased to announce the release of Apache Solr 8.3.0. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


CVE-2019-12401: XML Bomb in Apache Solr versions prior to 5.0

Security: 9 September 2019

Severity: Medium Vendor: The Apache Software Foundation Versions Affected: 1.3.0 to 1.4.1 3.1.0 to 3.6.2 4.0.0 to 4.10.4 Description: Solr versions prior to 5.0.0 are vulnerable to an XML resource consumption attack (a.k.a. Lol …


[ANNOUNCE] 8.1.1 and 8.2.0 users check ENABLE_REMOTE_JMX_OPTS setting

Security: 14 August 2019

Severity: Low Versions Affected: 8.1.1 and 8.2.0 for Linux Description: It has been discovered [1] that the 8.1.1 and 8.2.0 releases contain a bad default setting for the ENABLE_REMOTE_JMX_OPTS setting in the default solr.in.sh file shipping with Solr. Windows users …


CVE-2019-0193: Apache Solr, Remote Code Execution via DataImportHandler

Security: 31 July 2019

Severity: High Vendor: The Apache Software Foundation Versions Affected: 5.0.0 to 5.5.5 6.0.0 to 6.6.5 Description: The DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can …


Apache Solr™ 8.2.0 available

News: 26 July 2019

The Lucene PMC is pleased to announce the release of Apache Solr 8.2.0 Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document (e.g …


Apache Solr™ 7.7.2 available

News: 4 June 2019

The Lucene PMC is pleased to announce the release of Apache Solr 7.7.2. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and …


Apache Solr™ 8.1.1 available

News: 28 May 2019

The Lucene PMC is pleased to announce the release of Apache Solr 8.1.1 Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document (e.g …


Apache Solr™ 8.1.0 available

News: 16 May 2019

The Lucene PMC is pleased to announce the release of Apache Solr 8.1.0 Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document (e.g …


Apache Solr™ 6.6.6 available

News: 5 April 2019

The Lucene PMC is pleased to announce the release of Apache Solr 6.6.6 Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search and analytics, rich document parsing, geospatial search, extensive …


Apache Solr™ 8.0.0 available

News: 14 March 2019

The Lucene PMC is pleased to announce the release of Apache Solr 8.0.0 Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document (e.g …


Apache Solr Reference Guide 7.7 available

News: 11 March 2019

The Lucene PMC is pleased to announce that the Solr Reference Guide for 7.7 is now available. This 1,431-page PDF is the definitive guide to using Apache Solr, the search server built on Lucene. The PDF Guide can be downloaded from: https://www.apache.org/dyn/closer.cgi …


CVE-2019-0192: Deserialization of untrusted data via jmx.serviceUrl in Apache Solr

Security: 6 March 2019

Severity: High Vendor: The Apache Software Foundation Versions Affected: 5.0.0 to 5.5.5 6.0.0 to 6.6.5 Description: ConfigAPI allows to configure Solr's JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of …


Apache Solr™ 7.7.1 available

News: 1 March 2019

The Lucene PMC is pleased to announce the release of Apache Solr 7.7.1 Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document (e.g …


CVE-2017-3164: SSRF issue in Apache Solr

Security: 12 February 2019

Severity: High Vendor: The Apache Software Foundation Versions Affected: Apache Solr versions from 1.3 to 7.6.0 Description: The "shards" parameter does not have a corresponding whitelist mechanism, so it can request any URL. Mitigation: Upgrade to Apache Solr 7.7.0 or later. Ensure your network settings …


Apache Solr™ 7.7.0 available

News: 11 February 2019

The Lucene PMC is pleased to announce the release of Apache Solr 7.7.0 Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document (e.g …


Apache Solr™ 7.6.0 available

News: 14 December 2018

The Lucene PMC is pleased to announce the release of Apache Solr 7.6.0 Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document (e.g …


Apache Solr™ 7.5.0 available

News: 24 September 2018

The Lucene PMC is pleased to announce the release of Apache Solr 7.5.0 Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document (e.g …