Enterprise users can address the issues by installing 4.0.1 Enterprise. Community users can refer to the following two Jira tickets to understand how to address the issues in their installations:
SOLR REST API allows unauthenticated access to repository contents (ALF-13721)
Remote code execution possible via Web Script XSLT Processor (ALF-13726)