CVE-2024-8373 Affecting solr package, versions <9.8.1-r0


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.01% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-SOLR-14889914
  • published7 Jan 2026
  • disclosed9 Sept 2024

Introduced: 9 Sep 2024

CVE-2024-8373  (opens in a new tab)

How to fix?

Upgrade Chainguard solr to version 9.8.1-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream solr package and not the solr package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing .

This issue affects all versions of AngularJS.

Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

CVSS Base Scores

version 3.1