
CVE-2019-12409: RCE Vulnerability Due to Bad Defalut Config in Apache Solr
The 8.1.1 and 8.2.0 releases of Apache Solr contains insecure setting in the default solr.in.sh configuration file shipping with Solr. The setting that result in this vulnerability are:
In "solr.in.sh":
In "solr.cmd":
Note: Windows users are not affected.
The vendor's disclosure and fix for this vulnerability can be found here.
More details and the exploitation process can be found in this PDF.
PoC for exploiting CVE-2019-12409 using mjet
Another alternative tool for exploiting CVE-2019-12409 is beanshooter.