
Apache Solr Backup/Restore APIs RCE Poc (CVE-2023-50386)
Apache Solr Backup/Restore APIs RCE Poc (CVE-2023-50386)
References (respect to the masters):
CVE-2023-50386 vulnerability author's blog
Java Security Manager Bypass Techniques
Vulnerability exploitation principle and thoughts: https://mp.weixin.qq.com/s/mO4e8aiuL56yBdOD4jy2qQ
The POC is written using Pocsuite3. You can run it directly with the framework, or if you don't use the framework, you can extract its core implementation.
conf1.zip and conf2.zip can be used directly.
If you need to test and compile yourself, the Java exploits are under src, containing all the exploits I tested and can use.
POC execution effect:
Verification

Code Execution
