CVE-2019-17558

HIGHNVD 7.59.0
EchelonGraph scoreHIGH confidence

Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 7.5 retained for reference. Confidence: HIGH.

Triggered by: CISA KEV (actively exploited)
Sources: cisa_kev, epss, nvd
Trending — 3 sources updated this weekExploited in the wild
7.5
EchelonGraph verdictPatch nowTreat as an emergency — this is being exploited.
  • Actively exploited in the wild (CISA-KEV)
CISA-KEV: ExploitedEPSS: 99%CVSS: 7.5Exploit: NoneExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset velocity/ directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting params.resource.loader.enabled by defining a response writer with that setting set to true. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is trusted (has been uploaded by an authenticated user).

CVSS v3
7.5
EG Score
9.0(high)
EG Risk
EPSS
99.9%
KEV
⚠ Exploited

Published

December 30, 2019

Last Modified

October 27, 2025

Affected Packages

(1 across 1 ecosystem)
Maven(1)
PackageVulnerable rangeFixed inDependents
org.apache.solr:solr-core8.0.0 ... 8.3.1 (6 versions)8.4.0

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 8× in last 7d / 24× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-07-22 22:22 UTCEG score recompute
  2. 2026-07-22 19:40 UTCCISA KEV update
  3. 2026-07-21 14:37 UTCCISA KEV update
  4. 2026-07-20 18:50 UTCEG score recompute
  5. 2026-07-20 17:04 UTCEPSS rescore
  6. 2026-07-20 17:04 UTCEPSS rescore
  7. 2026-07-17 07:26 UTCEG score recompute
  8. 2026-07-16 17:04 UTCCISA KEV update
  9. 2026-07-15 16:49 UTCCISA KEV update
  10. 2026-07-15 15:04 UTCCISA KEV update
  11. 2026-07-14 18:05 UTCCISA KEV update
  12. 2026-07-13 17:07 UTCCISA KEV update
  13. 2026-07-10 17:52 UTCCISA KEV update
  14. 2026-07-09 19:06 UTCEPSS rescore
  15. 2026-07-07 19:01 UTCCISA KEV update
  16. 2026-07-07 17:16 UTCCISA KEV update
  17. 2026-07-01 19:16 UTCCISA KEV update
  18. 2026-06-29 19:12 UTCCISA KEV update
  19. 2026-06-28 04:54 UTCEPSS rescore
  20. 2026-06-28 04:54 UTCEPSS rescore
  21. 2026-06-25 19:15 UTCCISA KEV update
  22. 2026-06-23 21:31 UTCEPSS rescore
  23. 2026-06-23 21:30 UTCEPSS rescore
  24. 2026-06-23 17:44 UTCCISA KEV update
  25. 2026-06-18 16:13 UTCCISA KEV update
Show 17 more
  1. 2026-06-16 19:33 UTCCISA KEV update
  2. 2026-06-15 19:33 UTCCISA KEV update
  3. 2026-06-15 17:45 UTCEPSS rescore
  4. 2026-06-12 17:35 UTCCISA KEV update
  5. 2026-06-11 19:10 UTCCISA KEV update
  6. 2026-06-09 18:42 UTCCISA KEV update
  7. 2026-06-09 17:12 UTCCISA KEV update
  8. 2026-06-08 19:16 UTCCISA KEV update
  9. 2026-06-08 17:26 UTCCISA KEV update
  10. 2026-06-05 22:43 UTCCISA KEV update
  11. 2026-06-03 19:09 UTCCISA KEV update
  12. 2026-06-02 18:32 UTCCISA KEV update
  13. 2026-06-01 20:42 UTCCISA KEV update
  14. 2026-05-29 22:20 UTCCISA KEV update
  15. 2026-05-27 20:35 UTCCISA KEV update
  16. 2026-05-26 19:18 UTCEG score recompute
  17. 2026-05-26 19:13 UTCCISA KEV update

Publicly available exploits

(6 references)

Working exploit code is in the public domain (1 Metasploit module) (2 GitHub PoCs) (2 Exploit-DB entries). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.

  • GitHub PoCMa1Dong/Solr_CVE-2019-17558
    First seen Aug 4, 2020

    Solr_CVE-2019-17558

    Open source ↗
  • Exploit-DBEDB-48338✓ verified
    First seen Apr 16, 2020

    Apache Solr - Remote Code Execution via Velocity Template (Metasploit)

    Open source ↗
  • GitHub PoCzhzyker/exphub
    First seen Apr 1, 2020

    Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340

    Open source ↗
  • Exploit-DBEDB-47572
    First seen Nov 1, 2019

    Apache Solr 8.2.0 - Remote Code Execution

    Open source ↗
  • Metasploitexploit/multi/http/solr_velocity_rce✓ verified
    First seen Oct 29, 2019

    Apache Solr Remote Code Execution via Velocity Template

    Open source ↗
  • Nucleihttp/cves/2019/CVE-2019-17558.yaml
    First seen Jan 1, 2019

    Apache Solr <=8.3.1 - Remote Code Execution

    Open source ↗

Frequently asked(6)

What is CVE-2019-17558?
CVE-2019-17558 is a high vulnerability published on December 30, 2019. Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset velocity/ directory or as a parameter. A user defined configset could contain renderable, potentially…
When was CVE-2019-17558 disclosed?
CVE-2019-17558 was first published in the National Vulnerability Database on December 30, 2019, with the most recent update on October 27, 2025. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2019-17558 actively exploited?
Yes. CISA added CVE-2019-17558 to the Known Exploited Vulnerabilities catalog on November 3, 2021, affecting Apache Solr. KEV listing indicates confirmed exploitation in the wild; this CVE warrants immediate patching attention.
What is the CVSS score of CVE-2019-17558?
CVE-2019-17558 has a CVSS v3 base score of 7.5 (NVD). EchelonGraph synthesises NVD + CISA KEV + FIRST EPSS + GHSA into a combined EG score of 9.0.
Which products are affected by CVE-2019-17558?
CVE-2019-17558 affects Apache Solr. The full affected-products list, including version ranges and fixed versions, is shown in the Affected Packages section of this page.
How do I remediate CVE-2019-17558?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2019-17558, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2019-17558

Explore →

Is Your Infrastructure Affected by CVE-2019-17558?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.