CVE-2024-52012Disclosure(apache / solr)

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache solr systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload" API.  Commonly known as a "zipslip", maliciously constructed ZIP files can use relative filepaths to write data to unanticipated parts of the filesystem.   This issue affects Apache Solr: from 6.6 through 9.7.0. Users are recommended to upgrade to version 9.8.0, which fixes the issue.  Users unable to upgrade may also safely prevent the issue by using Solr's "Rule-Based Authentication Plugin" to restrict access to the configset upload API, so that it can only be accessed by a trusted set of administrators/users.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • solr

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
solr

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-09: 1Patch / Workaround · 2026-04-11: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-11: 104-0904-11
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure1General1
2026-04-111
Patch1
Full discourse3 posts
  • Nicolas Krassas@Dinosn
    General

    CVE-2024-52012 Apache Solr Path Traversal RCE Attack https://blog.securelayer7.net/cve-2024-52012-apache-solr-zip-slip-rce-attack/

    Post summary

    The snippet announces CVE‑2024‑52012 as an Apache Solr path‑traversal flaw that enables remote code execution, linking to a blog likely detailing the vulnerability scenario.

    1701821.6K
    157.5K followersView on X
  • Mr. OS@ksg93rd
    Patch

    #Analytics #Threat_Research An analytical review of the main cybersecurity events for the week (Apr.4-11, 2026) 1⃣. OpenSSL maintenance releases https://github.com/openssl/openssl/tags // OpenSSL 3.6.2, 3.5.6, 3.4.5, 3.3.7, which fix 7 vulnerabilities, incl. CVE-2026-31790 https://github.com/advisories/GHSA-vgxx-5xj5-q97x 2⃣. GlassWorm goes native: New Zig dropper infects every IDE on your machine https://www.aikido.dev/blog/glassworm-zig-dropper-infects-every-ide-on-your-machine // Extension impersonates WakaTime, popular developer time-tracking tool, and ships a Zig-compiled native binary alongside its JavaScript code 3⃣. Claude Mythos - new LLM from Anthropic https://www.anthropic.com/glasswing // Assessing Claude Mythos cybersecurity capabilities https://red.anthropic.com/2026/mythos-preview/ 4⃣. Node.js Trust Falls: https://www.zerodayinitiative.com/blog/2026/4/8/nodejs-trust-falls-dangerous-module-resolution-on-windows Dangerous Module Resolution on Windows // Node.js on Windows defaults to insecure module resolution in C:\node_modules, enabling privilege escalation, with major vendors dismissing the security risk despite longstanding awareness since 2013... 5⃣. High-tech vulnerability in PDF files https://justhaifei1.blogspot.com/2026/04/expmon-detected-sophisticated-zero-day-adobe-reader.html // Such a mechanism allows the threat actor to collect user information, steal local data, perform advanced fingerprinting, and launch future attacks: if the target meets the attacker's conditions, the attacker may deliver additional exploit to achieve RCE/SBX 6⃣. Apache Solr Path Traversal RCE Attack https://blog.securelayer7.net/cve-2024-52012-apache-solr-zip-slip-rce-attack/ // CVE-2024-52012 is a Zip Slip vulnerability in Apache Solr’s ConfigSet Upload API allowing unauthenticated RCE via crafted ZIP files with path traversal sequences 7⃣. Microsoft Speech https://ipurple.team/2026/04/07/microsoft-speech/ // SpeechRuntime.exe can be exploited for lateral movement through COM hijacking and session enumeration

    Post summary

    The article enumerates recent CVEs, highlighting OpenSSL patches, and supplies technical details for several vulnerabilities, but does not provide PoC, exploit code, or evidence of active exploitation.

    00001173
    3.3K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    CVE-2024-52012 Apache Solr Zip Slip flaw enables unauthenticated path traversal, arbitrary file write, and full RCE via ConfigSet upload API in vulnerable deployments. https://blog.securelayer7.net/cve-2024-52012-apache-solr-zip-slip-rce-attack/

    Post summary

    The blog post announces CVE‑2024‑52012, detailing how an unauthenticated path‑traversal flaw in Apache Solr allows arbitrary file writes and full remote code execution via the ConfigSet upload API.

    00010231
    2.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachesolr---

Explore more