Internal Solr Query Injection enabling Local FIle Inclusion and Potential SSRF on trek.nasa.gov

Disclosed by
YeJunWon
Summary by YeJunWon

The server forwards a q query to an internal network based on Apache Solr using a uuid query parameter.

An attacker can inject a new query into the internal network by using %26.

By controlling the Solr shards parameter via query injection, an attacker can gain access to internal resources through the internal Solr instance.

Activity