Potential CVE-2021-27905 Exploitation Attempt Against Apache Solr via Specific HTTP Requests

Alerts when webserver logs show GET requests to Solr endpoints containing CVE-2021-27905-style debug/dump or fetchindex parameters with HTTP 200.

FreeUnreviewedSigmamediumv1
title: Potential CVE-2021-27905 Exploitation Attempt Against Apache Solr via Specific HTTP Requests
id: 61c7c1db-ed83-40ca-b0cf-b85646ff1fcf
status: test
description: This rule flags Apache Solr exploitation attempts consistent with CVE-2021-27905 by matching HTTP requests that include characteristic query parameters used in dump or fetchindex-style behaviors. Attackers may use these crafted requests to trigger unintended functionality such as reading sensitive data or reaching back to attacker-controlled URLs. The detection relies on webserver HTTP telemetry fields for the request URI query content, HTTP method, and resulting response status codes.
references:
  - https://twitter.com/Al1ex4/status/1382981479727128580
  - https://twitter.com/sec715/status/1373472323538362371
  - https://nsfocusglobal.com/apache-solr-arbitrary-file-read-and-ssrf-vulnerability-threat-alert/
  - https://mp.weixin.qq.com/s?__biz=Mzg3NDU2MTg0Ng==&mid=2247484117&idx=1&sn=2fdab8cbe4b873f8dd8abb35d935d186
  - https://github.com/murataydemir/CVE-2021-27905
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Exploits/CVE-2021-27905/web_cve_2021_27905_apache_solr_exploit.yml
author: "@gott_cyber, Huntrule Team"
date: 2022-12-11
modified: 2023-03-24
tags:
  - attack.initial-access
  - attack.t1190
  - cve.2021-27905
  - detection.emerging-threats
logsource:
  category: webserver
detection:
  selection_request1:
    cs-uri-query|contains|all:
      - /solr/
      - /debug/dump?
      - param=ContentStream
    sc-status: 200
  selection_request2:
    cs-method: GET
    cs-uri-query|contains|all:
      - /solr/
      - command=fetchindex
      - masterUrl=
    sc-status: 200
  condition: 1 of selection_*
falsepositives:
  - Vulnerability Scanners
level: medium
license: DRL-1.1
related:
  - id: 0bbcd74b-0596-41a4-94a0-4e88a76ffdb3
    type: derived

What it detects

This rule flags Apache Solr exploitation attempts consistent with CVE-2021-27905 by matching HTTP requests that include characteristic query parameters used in dump or fetchindex-style behaviors. Attackers may use these crafted requests to trigger unintended functionality such as reading sensitive data or reaching back to attacker-controlled URLs. The detection relies on webserver HTTP telemetry fields for the request URI query content, HTTP method, and resulting response status codes.

Known false positives

  • Vulnerability Scanners

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.