---
title: "CVE-2018-8010\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2018-8010?format=md
keywords: index, follow
---

# CVE-2018-8010

Publication date 21 May 2018

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2018-8010?format=md#impact-score)

Toggle side navigation

## Description

This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to
an XML external entity expansion (XXE) in Solr config files
(solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude
functionality provided in these config files is also affected in a similar
way. The vulnerability can be used as XXE using file/ftp/http protocols in
order to read arbitrary local files from the Solr server or the internal
network. Users are advised to upgrade to either Solr 6.6.4 or Solr 7.3.1
releases both of which address the vulnerability. Once upgrade is complete,
no other steps are required. Those releases only allow external entities
and Xincludes that refer to local files / zookeeper resources below the
Solr instance directory (using Solr's ResourceLoader); usage of absolute
URLs is denied. Keep in mind, that external entities and XInclude are
explicitly supported to better structure config files in large
installations. Before Solr 6 this was no problem, as config files were not
accessible through the APIs.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2018-8010?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| lucene-solr | 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

Versions 5.x and earlier are not affected by the vulnerability

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8010)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-8010)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2018-8010)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2018-8010)

### Other references

* <https://issues.apache.org/jira/browse/SOLR-12316>
* <https://mail-archives.apache.org/mod_mbox/www-announce/201805.mbox/%3C08a801d3f0f9%24df46d300%249dd47900%24%40apache.org%3E>
* <https://www.cve.org/CVERecord?id=CVE-2018-8010>
