ColdFusion 9 Solr Vulnerability - Are you at Risk?
Adobe just released a security bulletin APSB10-04 for ColdFusion 9. If you have the Solr Search Service running on a ColdFusion 9 server it binds the Solr Web Service to port 8983 on all IP addresses. Adobe has also released a Technote describing how to fix the issue.
Is your CF9 Server at Risk?
I've updated my ColdFusion Security Scanner: hackmycf.com to test for this issue. So you can just head over there and type in your domain / email to find out.
Adobe has classified this issue as Important not Critical, but if you are using the CF9 solr service to index sensitive data, it could very well be a critical issue for you to resolve. Also if any vulnerabilities are discovered in the Solr web service itself it may become critical. I am sure a denial of service attack would be pretty easy to perform given the tools the Solr Service exposes.
It also exposes a lot of system information, all the java system properties can be exposed by visiting: http://localhost:8983/solr/data_medialibrary/admin/get-properties.jsp, which exposes things such as:
- Operating System
- Operating System Patch Level
- ColdFusion Installation Paths
- Java Version Info
- Etc.
The good news is that if you have a network firewall in place, your firewall should be blocking requests for this port.
Given all you can do with this service, I would strongly recommend you do the following:
- Make sure your firewall blocks port 8983
- Disable the Solr Search Service if you are not using it.
- Follow the instructions in the technote to limit access to localhost.
Related Entries
- Hands on ColdFusion Security Training - February 4, 2010
- CFLogin Security Considerations - December 10, 2009
- FuseGuard Released - Protects your ColdFusion Apps - November 12, 2009
- Howto Require SSL for ColdFusion Administrator - October 23, 2009
- You May Need to Reapply CF Security Hotfix CVE-2009-1877 - October 22, 2009
Trackbacks
Trackback Address: 738/A8F2059DF8841E6272314A1CCFB28C98
Comments
On 02/10/2010 at 12:38:10 PM EST Justin wrote:
1
Pete, Thanks for the info. We're running CF6.2 in my environment. After scanning the available services at the server, I don't see a SOLR Search Service as an option. Was the SOLR Service available in version 6.2? I'm not a ColdFusion Professional, so please excuse the elementary question. Please let me know at your earliest convenience, as I'm trying to identify whether the patch for the web service will apply to my environment.
Thanks in Advance, Justin
On 02/10/2010 at 12:43:19 PM EST Pete Freitag wrote:
2
Hi Justin,
The Solr Search Service was added in ColdFusion version 9.0, so you do not need to worry about this for CF 1-8
Post a Comment
Recent Entries
- Cache Template in Request Setting Explained
- What Version of Java is ColdFusion Using?
- ColdFusion 9 Performance Brief from Adobe
- Request Filtering in IIS 7 Howto
- J2EE Session Cookies on ColdFusion / JRun
- Hands on ColdFusion Security Training
- FCKEditor Year 2010 Bug for Firefox 3.6 with ColdFusion
Thanks in Advance, Justin
The Solr Search Service was added in ColdFusion version 9.0, so you do not need to worry about this for CF 1-8



add to del.icio.us



