This is an automated email from the ASF dual-hosted git repository.
github-actions[bot] pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/solr-site.git
The following commit(s) were added to refs/heads/asf-staging by this push:
new b7f9740a8 Commit build products
b7f9740a8 is described below
commit b7f9740a8fb16030cf0b8052ab83aa462e034523
Author: Build Pelican (action) <[email protected]>
AuthorDate: Sun Jun 21 18:47:33 2026 +0000
Commit build products
---
output/feeds/all.atom.xml | 31 +++++-
output/feeds/solr/vex.atom.xml | 10 +-
output/security-dependency-cves.html | 65 +++++-------
output/solr.vex.json | 200 ++++++++++++++++++++++-------------
output/vex.html | 103 ++++++++----------
5 files changed, 234 insertions(+), 175 deletions(-)
diff --git a/output/feeds/all.atom.xml b/output/feeds/all.atom.xml
index 9a1400f02..d9c1aadd6 100644
--- a/output/feeds/all.atom.xml
+++ b/output/feeds/all.atom.xml
@@ -939,7 +939,8 @@ Therefore, Solr Clouds with Authorization setup will only
be vulnerable via user
Users are recommended to upgrade to version 9.3.0 or later, in which
environment variables are not published via the Metrics API.</p>
<p><strong>References:</strong><br>
JIRA - <a
href="https://issues.apache.org/jira/browse/SOLR-16808">SOLR-15233</a><br>
-CVE - <a
href="https://nvd.nist.gov/vuln/detail/CVE-2023-50290">CVE-2023-50290</a></p></content><category
term="solr/security"/></entry><entry><title>json-path</title><link
href="/cve-2023-51074.html"
rel="alternate"/><published>2024-01-12T00:00:00+00:00</published><updated>2024-01-12T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2024-01-12:/cve-2023-51074.html</id><summary
type="html"><p>The only places we use json-path is for [...]
+CVE - <a
href="https://nvd.nist.gov/vuln/detail/CVE-2023-50290">CVE-2023-50290</a></p></content><category
term="solr/security"/></entry><entry><title>json-path</title><link
href="/cve-2023-51074.html"
rel="alternate"/><published>2024-01-12T00:00:00+00:00</published><updated>2024-01-12T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2024-01-12:/cve-2023-51074.html</id><summary
type="html"><p>The only places we use json-path is for [...]
+<p>Regardless, Solr upgraded the bundled json-path to 2.9.0 — which
fixes CVE-2023-51074 — in Solr 9.6.0, so the vulnerable json-path (≤ 2.8.0)
only shipped through Solr 9.5.</p></content><category
term="solr/vex"/></entry><entry><title>Apache Solr Operator™ v0.8.0
available</title><link href="/apache-solr-operatortm-v080-available.html"
rel="alternate"/><published>2023-10-20T00:00:00+00:00</published><updated>2023-10-20T00:00:00+00:00</updated><author><name>Solr
Developers</ [...]
<p>The Apache Solr Operator is a safe and easy way of managing a Solr
ecosystem in Kubernetes.</p>
<p>This release contains numerous bug fixes, optimizations, and
improvements, some of which are highlighted below …</p></summary><content
type="html"><p>The Apache Solr PMC is pleased to announce the release of
the Apache Solr Operator v0.8.0.</p>
<p>The Apache Solr Operator is a safe and easy way of managing a Solr
ecosystem in Kubernetes.</p>
@@ -1131,7 +1132,14 @@ CVE - <a
href="https://nvd.nist.gov/vuln/detail/CVE-2023-50290">CVE-2023-5
<p>Please refer to the Upgrade Notes in the Solr Ref Guide for
information on upgrading from previous Solr versions:</p>
<p><a
href="https://solr.apache.org/guide/solr/9_1/upgrade-notes/solr-upgrade-notes.html">https://solr.apache.org/guide/solr/9_1/upgrade-notes/solr-upgrade-notes.html</a></p>
<p>Please read CHANGES.txt for a full list of bugfixes:</p>
-<p><a
href="https://solr.apache.org/9_1_1/changes/Changes.html">https://solr.apache.org/9_1_1/changes/Changes.html</a></p></content><category
term="solr/news"/></entry><entry><title>xercesImpl</title><link
href="/cve-2012-0881.html"
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2022-12-14:/cve-2012-0881.html</id><content
type="html"><p>Onl [...]
+<p><a
href="https://solr.apache.org/9_1_1/changes/Changes.html">https://solr.apache.org/9_1_1/changes/Changes.html</a></p></content><category
term="solr/news"/></entry><entry><title>xercesImpl</title><link
href="/cve-2012-0881.html"
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2022-12-14:/cve-2012-0881.html</id><content
type="html"><p>Onl [...]
+transitive dependency on <code>struts-core</code>,
<code>struts-taglib</code> and
<code>struts-tiles</code> 1.3.8. Solr does not
+ship any Struts jar — the dependency is excluded and only appears as a
transitive POM listing
+(see SOLR-2849) — so these Struts vulnerabilities
…</p></summary><content type="html"><p>Scanners flag
<code>velocity-tools-2.0.jar</code> with Apache Struts 1 CVEs
because its POM declares a
+transitive dependency on <code>struts-core</code>,
<code>struts-taglib</code> and
<code>struts-tiles</code> 1.3.8. Solr does not
+ship any Struts jar — the dependency is excluded and only appears as a
transitive POM listing
+(see SOLR-2849) — so these Struts vulnerabilities are not present in, or
exploitable through, Solr.</p></content><category
term="solr/vex"/></entry><entry><title>vorbis-java-tika</title><link
href="/cve-2016-6809.html"
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2022-12-14:/cve-2016-6809.html</id><content
type="html"><p>See https://github.com/Gagravarr/Vo [...]
+<p>Tika as an in-process component was removed in Solr
9.11.</p></content><category
term="solr/vex"/></entry><entry><title>org.restlet</title><link
href="/cve-2017-14868.html"
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2022-12-14:/cve-2017-14868.html</id><content
type="html"><p>Solr should not be exposed outside a firewall where bad
actors can send [...]
Solr 6.5 to 8.11.2
Solr 9.0</p>
<p><strong>Description:</strong><br>
@@ -1558,4 +1566,21 @@ See <a
href="https://lists.apache.org/thread/kgh63sncrsm2bls884pg87mnt8vqztmz
<p>A summary of important changes is published in the documentation
at:</p>
<p><a
href="https://apache.github.io/solr-operator/docs/upgrade-notes.html">https://apache.github.io/solr-operator/docs/upgrade-notes.html</a></p>
<p>For the most exhaustive list, see the full release notes in the
Github Releases or by viewing the git history in the solr-operator
repo.</p>
-<p><a
href="https://github.com/apache/solr-operator/releases/tag/v0.3.0">https://github.com/apache/solr-operator/releases/tag/v0.3.0</a></p></content><category
term="solr/operator/news"/></entry></feed>
\ No newline at end of file
+<p><a
href="https://github.com/apache/solr-operator/releases/tag/v0.3.0">https://github.com/apache/solr-operator/releases/tag/v0.3.0</a></p></content><category
term="solr/operator/news"/></entry><entry><title>Apache Solr™ 8.8.2
available</title><link href="/apache-solrtm-882-available.html"
rel="alternate"/><published>2021-04-12T00:00:00+00:00</published><updated>2021-04-12T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2021-04-1 [...]
+<p>Solr is the popular, blazing fast, open source NoSQL search platform
from the Apache Lucene project. Its major features include powerful full-text
search, hit highlighting, faceted search, dynamic clustering, database
integration, rich document handling, and …</p></summary><content
type="html"><p>The Solr PMC is pleased to announce the release of Apache
Solr 8.8.2.</p>
+<p>Solr is the popular, blazing fast, open source NoSQL search platform
from the Apache Lucene project. Its major features include powerful full-text
search, hit highlighting, faceted search, dynamic clustering, database
integration, rich document handling, and geospatial search. Solr is highly
scalable, providing fault tolerant distributed search and indexing, and powers
the search and navigation features of many of the world's largest internet
sites.</p>
+<p>Solr 8.8.2 is available for immediate download at:</p>
+<p><a
href="https://solr.apache.org/downloads.html">https://solr.apache.org/downloads.html</a></p>
+<h3 id="solr-882-release-highlights">Solr 8.8.2 Release Highlights:<a
class="headerlink" href="#solr-882-release-highlights" title="Permanent
link">&para;</a></h3>
+<ul>
+<li>SOLR-15249: Properly set ZK ACLs on /security.json</li>
+<li>SOLR-15233: Set doAs param in
ConfigurableInternodeAuthHadoopPlugin</li>
+<li>SOLR-15217: Use shardsWhitelist in ReplicationHandler</li>
+<li>SOLR-15288: Hardening NODEDOWN event in collections using
PerReplicaStates</li>
+</ul>
+<p>Please refer to the Upgrade Notes in the Solr Ref Guide for
information on upgrading from previous Solr versions:</p>
+<p><a
href="https://solr.apache.org/guide/8_8/solr-upgrade-notes.html">https://solr.apache.org/guide/8_8/solr-upgrade-notes.html</a></p>
+<p>Please read CHANGES.txt for a full list of bugfixes:</p>
+<p><a
href="https://solr.apache.org/8_8_2/changes/Changes.html">https://solr.apache.org/8_8_2/changes/Changes.html</a></p>
+<p>Solr 8.8.2 also includes bugfixes in the corresponding Apache Lucene
release:</p>
+<p><a
href="https://lucene.apache.org/core/8_8_2/changes/Changes.html">https://lucene.apache.org/core/8_8_2/changes/Changes.html</a></p></content><category
term="solr/news"/></entry></feed>
\ No newline at end of file
diff --git a/output/feeds/solr/vex.atom.xml b/output/feeds/solr/vex.atom.xml
index 8bf259b38..15ca522e1 100644
--- a/output/feeds/solr/vex.atom.xml
+++ b/output/feeds/solr/vex.atom.xml
@@ -175,4 +175,12 @@ These replacements are incorrectly treated as "trusted"
and can leverage <cod
<p>Users can protect against the vulnerability by enabling
authentication and authorization on their Solr clusters or switching to
SolrCloud (and away from "FileSystemConfigSetService").
Users are also recommended to upgrade to Solr 9.8.0, which mitigates this
issue by disabling use of "<lib>" tags by default.</p>
<h4 id="credit">Credit<a class="headerlink" href="#credit"
title="Permanent link">&para;</a></h4>
-<p>pwn null (reporter)</p></content><category
term="solr/vex"/></entry><entry><title>json-path</title><link
href="/cve-2023-51074.html"
rel="alternate"/><published>2024-01-12T00:00:00+00:00</published><updated>2024-01-12T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2024-01-12:/cve-2023-51074.html</id><summary
type="html"><p>The only places we use json-path is for querying (via
Calcite) and for transforming/indexing custom JSON. Since [...]
\ No newline at end of file
+<p>pwn null (reporter)</p></content><category
term="solr/vex"/></entry><entry><title>json-path</title><link
href="/cve-2023-51074.html"
rel="alternate"/><published>2024-01-12T00:00:00+00:00</published><updated>2024-01-12T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2024-01-12:/cve-2023-51074.html</id><summary
type="html"><p>The only places we use json-path is for querying (via
Calcite) and for transforming/indexing custom JSON. Since [...]
+<p>Regardless, Solr upgraded the bundled json-path to 2.9.0 — which
fixes CVE-2023-51074 — in Solr 9.6.0, so the vulnerable json-path (≤ 2.8.0)
only shipped through Solr 9.5.</p></content><category
term="solr/vex"/></entry><entry><title>xercesImpl</title><link
href="/cve-2012-0881.html"
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2022-12-14:/cve-2012-0881 [...]
+transitive dependency on <code>struts-core</code>,
<code>struts-taglib</code> and
<code>struts-tiles</code> 1.3.8. Solr does not
+ship any Struts jar — the dependency is excluded and only appears as a
transitive POM listing
+(see SOLR-2849) — so these Struts vulnerabilities
…</p></summary><content type="html"><p>Scanners flag
<code>velocity-tools-2.0.jar</code> with Apache Struts 1 CVEs
because its POM declares a
+transitive dependency on <code>struts-core</code>,
<code>struts-taglib</code> and
<code>struts-tiles</code> 1.3.8. Solr does not
+ship any Struts jar — the dependency is excluded and only appears as a
transitive POM listing
+(see SOLR-2849) — so these Struts vulnerabilities are not present in, or
exploitable through, Solr.</p></content><category
term="solr/vex"/></entry><entry><title>vorbis-java-tika</title><link
href="/cve-2016-6809.html"
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2022-12-14:/cve-2016-6809.html</id><content
type="html"><p>See https://github.com/Gagravarr/Vo [...]
+<p>Tika as an in-process component was removed in Solr
9.11.</p></content><category
term="solr/vex"/></entry><entry><title>org.restlet</title><link
href="/cve-2017-14868.html"
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2022-12-14:/cve-2017-14868.html</id><content
type="html"><p>Solr should not be exposed outside a firewall where bad
actors can send [...]
\ No newline at end of file
diff --git a/output/security-dependency-cves.html
b/output/security-dependency-cves.html
index e5f23c9b2..a96bb706e 100644
--- a/output/security-dependency-cves.html
+++ b/output/security-dependency-cves.html
@@ -223,7 +223,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51504">CVE-2024-51504</a>
</td>
- <td>9.4.0–9.8.1</td>
+ <td>9.4.0-9.8.1</td>
<td>
zookeeper-3.9.0.jar, zookeeper-3.9.1.jar,
zookeeper-3.9.2.jar </td>
<td>not affected</td>
@@ -232,7 +232,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6763">CVE-2024-6763</a>
</td>
- <td>< 9.8</td>
+ <td>≤ 9.7</td>
<td>
jetty-http-10.0.22.jar </td>
<td>not affected</td>
@@ -241,7 +241,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51074">CVE-2023-51074</a>,
<a
href="https://github.com/advisories/GHSA-pfh2-hfmq-phg5">GHSA-pfh2-hfmq-phg5</a>
</td>
- <td>all</td>
+ <td>≤ 9.5</td>
<td>
json-path-2.8.0.jar </td>
<td>not affected</td>
@@ -249,26 +249,8 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
</tr>
<tr>
<td>
- </td>
- <td>6.6.2-today</td>
- <td>
- velocity-tools-2.0.jar </td>
- <td>not affected</td>
- <td><a href="/vex.html#cve-velocity-tools">velocity-tools</a></td>
- </tr>
- <tr>
- <td>
- </td>
- <td>7.3.1-today</td>
- <td>
- tika-core.*.jar </td>
- <td>not affected</td>
- <td><a href="/vex.html#cve-tika-core">tika-core.*</a></td>
- </tr>
- <tr>
- <td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42889">CVE-2022-42889</a>
</td>
- <td>< 9.1</td>
+ <td>≤ 9.0</td>
<td>
commons-text-1.9.jar </td>
<td>not affected</td>
@@ -277,7 +259,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33980">CVE-2022-33980</a>
</td>
- <td>< 9.1</td>
+ <td>≤ 9.0</td>
<td>
commons-configuration2-2.7.jar </td>
<td>not affected</td>
@@ -286,7 +268,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25168">CVE-2022-25168</a>
</td>
- <td>< 9.1</td>
+ <td>≤ 9.0</td>
<td>
hadoop-common-3.2.2.jar </td>
<td>not affected</td>
@@ -313,7 +295,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33813">CVE-2021-33813</a>
</td>
- <td>to present</td>
+ <td>≤ 8.x</td>
<td>
jdom-*.jar </td>
<td>not affected</td>
@@ -322,7 +304,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27223">CVE-2020-27223</a>
</td>
- <td>7.3.0-present</td>
+ <td>7.3.0-8.x</td>
<td>
jetty-9.4.6 to 9.4.36 </td>
<td>not affected</td>
@@ -340,7 +322,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13955">CVE-2020-13955</a>
</td>
- <td>8.1.0- today</td>
+ <td>8.1.0-8.x</td>
<td>
avatica-core-1.13.0.jar, calcite-core-1.18.0.jar </td>
<td>not affected</td>
@@ -376,7 +358,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2018-8088">CVE-2018-8088</a>
</td>
- <td>4.x-today</td>
+ <td>4.x-9.1</td>
<td>
slf4j-api-1.7.24.jar, jcl-over-slf4j-1.7.24.jar,
jul-to-slf4j-1.7.24.jar </td>
<td>not affected</td>
@@ -403,7 +385,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10237">CVE-2018-10237</a>
</td>
- <td>5.4.0-today</td>
+ <td>5.4.0-8.x</td>
<td>
carrot2-guava-18.0.jar </td>
<td>not affected</td>
@@ -412,7 +394,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10237">CVE-2018-10237</a>
</td>
- <td>4.6.0-today</td>
+ <td>4.6.0-8.x</td>
<td>
guava-*.jar </td>
<td>not affected</td>
@@ -421,7 +403,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000632">CVE-2018-1000632</a>
</td>
- <td>4.6.0-today</td>
+ <td>4.6.0-8.x</td>
<td>
dom4j-1.6.1.jar </td>
<td>not affected</td>
@@ -448,7 +430,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15095">CVE-2017-15095</a>,
<a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17485">CVE-2017-17485</a>,
<a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7525">CVE-2017-7525</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2018-5968">CVE-2018-5968</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2018-7489">CVE-2018-7489</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2019-12086">CVE-2019-12086</a>, <a
href="https://nvd.nist.gov/ [...]
- <td>4.7.0-today</td>
+ <td>4.7.0-8.x</td>
<td>
jackson-databind-*.jar </td>
<td>not affected</td>
@@ -466,7 +448,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14868">CVE-2017-14868</a>,
<a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14949">CVE-2017-14949</a>
</td>
- <td>5.2.0-today</td>
+ <td>5.2.0-8.x</td>
<td>
org.restlet-2.3.0.jar </td>
<td>not affected</td>
@@ -475,7 +457,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6809">CVE-2016-6809</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1335">CVE-2018-1335</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1338">CVE-2018-1338</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1339">CVE-2018-1339</a>
</td>
- <td>5.5.5, 6.2.0-today</td>
+ <td>5.5.5, 6.2.0-9.10</td>
<td>
vorbis-java-tika-0.8.jar </td>
<td>not affected</td>
@@ -483,8 +465,17 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
</tr>
<tr>
<td>
+<a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0899">CVE-2015-0899</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2016-1181">CVE-2016-1181</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2016-1182">CVE-2016-1182</a>
</td>
+ <td>6.6.2-8.x</td>
+ <td>
+ velocity-tools-2.0.jar </td>
+ <td>not affected</td>
+ <td><a href="/vex.html#cve-2016-1181">Apache Struts 1 CVEs via
velocity-tools transitive dependency</a></td>
+ </tr>
+ <tr>
+ <td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5237">CVE-2015-5237</a>
</td>
- <td>6.5.0-today</td>
+ <td>6.5.0-7.x</td>
<td>
protobuf-java-3.1.0.jar </td>
<td>not affected</td>
@@ -511,7 +502,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2098">CVE-2012-2098</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1324">CVE-2018-1324</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2018-11771">CVE-2018-11771</a>
</td>
- <td>4.6.0-today</td>
+ <td>4.6.0-7.x</td>
<td>
commons-compress (only as part of Ant 1.8.2) </td>
<td>not affected</td>
@@ -520,7 +511,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0881">CVE-2012-0881</a>
</td>
- <td>~2.9-today</td>
+ <td>2.9-9.10</td>
<td>
xercesImpl-2.9.1.jar </td>
<td>not affected</td>
diff --git a/output/solr.vex.json b/output/solr.vex.json
index 496b4dbfc..fc3be49c6 100644
--- a/output/solr.vex.json
+++ b/output/solr.vex.json
@@ -7,7 +7,7 @@
"name": "solr",
"version": "SNAPSHOT",
"type": "application",
- "bom-ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "bom-ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
},
"vulnerabilities": [
@@ -23,7 +23,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -39,7 +39,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -55,7 +55,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -71,7 +71,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -87,7 +87,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -103,7 +103,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -119,7 +119,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -135,7 +135,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -151,7 +151,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -167,7 +167,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -183,7 +183,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -199,7 +199,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -215,7 +215,55 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
+ }
+ ]
+ },
+ {
+ "id": "CVE-2015-0899",
+ "source": {
+ "name": "NVD",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-0899"
+ },
+ "analysis": {
+ "state": "not_affected",
+ "detail": "Scanners flag `velocity-tools-2.0.jar` with Apache Struts 1
CVEs because its POM declares a\ntransitive dependency on `struts-core`,
`struts-taglib` and `struts-tiles` 1.3.8. Solr does not\nship any Struts jar
\u2014 the dependency is excluded and only appears as a transitive POM
listing\n(see SOLR-2849) \u2014 so these Struts vulnerabilities are not present
in, or exploitable through, Solr."
+ },
+ "affects": [
+ {
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
+ }
+ ]
+ },
+ {
+ "id": "CVE-2016-1181",
+ "source": {
+ "name": "NVD",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-1181"
+ },
+ "analysis": {
+ "state": "not_affected",
+ "detail": "Scanners flag `velocity-tools-2.0.jar` with Apache Struts 1
CVEs because its POM declares a\ntransitive dependency on `struts-core`,
`struts-taglib` and `struts-tiles` 1.3.8. Solr does not\nship any Struts jar
\u2014 the dependency is excluded and only appears as a transitive POM
listing\n(see SOLR-2849) \u2014 so these Struts vulnerabilities are not present
in, or exploitable through, Solr."
+ },
+ "affects": [
+ {
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
+ }
+ ]
+ },
+ {
+ "id": "CVE-2016-1182",
+ "source": {
+ "name": "NVD",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-1182"
+ },
+ "analysis": {
+ "state": "not_affected",
+ "detail": "Scanners flag `velocity-tools-2.0.jar` with Apache Struts 1
CVEs because its POM declares a\ntransitive dependency on `struts-core`,
`struts-taglib` and `struts-tiles` 1.3.8. Solr does not\nship any Struts jar
\u2014 the dependency is excluded and only appears as a transitive POM
listing\n(see SOLR-2849) \u2014 so these Struts vulnerabilities are not present
in, or exploitable through, Solr."
+ },
+ "affects": [
+ {
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -227,11 +275,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30;
reported CVEs are not related to OggVorbis at all."
+ "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30;
reported CVEs are not related to OggVorbis at all.\n\nTika as an in-process
component was removed in Solr 9.11."
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -243,11 +291,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30;
reported CVEs are not related to OggVorbis at all."
+ "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30;
reported CVEs are not related to OggVorbis at all.\n\nTika as an in-process
component was removed in Solr 9.11."
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -259,11 +307,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30;
reported CVEs are not related to OggVorbis at all."
+ "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30;
reported CVEs are not related to OggVorbis at all.\n\nTika as an in-process
component was removed in Solr 9.11."
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -275,11 +323,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30;
reported CVEs are not related to OggVorbis at all."
+ "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30;
reported CVEs are not related to OggVorbis at all.\n\nTika as an in-process
component was removed in Solr 9.11."
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -295,7 +343,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -311,7 +359,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -327,7 +375,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -343,7 +391,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -359,7 +407,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -375,7 +423,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -391,7 +439,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -407,7 +455,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -423,7 +471,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -439,7 +487,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -455,7 +503,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -471,7 +519,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -487,7 +535,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -503,7 +551,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -519,7 +567,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -535,7 +583,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -551,7 +599,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -567,7 +615,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -583,7 +631,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -599,7 +647,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -615,7 +663,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -631,7 +679,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -647,7 +695,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -663,7 +711,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -679,7 +727,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -695,7 +743,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -711,7 +759,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -727,7 +775,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -743,7 +791,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -759,7 +807,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -775,7 +823,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -791,7 +839,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -807,7 +855,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -823,7 +871,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -839,7 +887,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -855,7 +903,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -871,7 +919,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -887,7 +935,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -903,7 +951,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -922,7 +970,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -938,7 +986,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -950,11 +998,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "The only places we use json-path is for querying (via
Calcite) and for transforming/indexing custom JSON. Since the advisory
describes a problem that is limited to the current thread, and users that are
allowed to query/transform/index are already trusted to cause load to some
extent, this advisory does not appear to have impact on the way json-path is
used in Solr."
+ "detail": "The only places we use json-path is for querying (via
Calcite) and for transforming/indexing custom JSON. Since the advisory
describes a problem that is limited to the current thread, and users that are
allowed to query/transform/index are already trusted to cause load to some
extent, this advisory does not appear to have impact on the way json-path is
used in Solr.\n\nRegardless, Solr upgraded the bundled json-path to 2.9.0
\u2014 which fixes CVE-2023-51074 \u2014 in [...]
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -966,11 +1014,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "The only places we use json-path is for querying (via
Calcite) and for transforming/indexing custom JSON. Since the advisory
describes a problem that is limited to the current thread, and users that are
allowed to query/transform/index are already trusted to cause load to some
extent, this advisory does not appear to have impact on the way json-path is
used in Solr."
+ "detail": "The only places we use json-path is for querying (via
Calcite) and for transforming/indexing custom JSON. Since the advisory
describes a problem that is limited to the current thread, and users that are
allowed to query/transform/index are already trusted to cause load to some
extent, this advisory does not appear to have impact on the way json-path is
used in Solr.\n\nRegardless, Solr upgraded the bundled json-path to 2.9.0
\u2014 which fixes CVE-2023-51074 \u2014 in [...]
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -989,7 +1037,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -1005,7 +1053,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -1022,7 +1070,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -1038,7 +1086,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -1055,7 +1103,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -1072,7 +1120,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -1089,7 +1137,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -1106,7 +1154,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
},
@@ -1123,7 +1171,7 @@
},
"affects": [
{
- "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+ "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
}
]
}
diff --git a/output/vex.html b/output/vex.html
index f272f9da7..a350724fd 100644
--- a/output/vex.html
+++ b/output/vex.html
@@ -415,7 +415,7 @@ with <code>log4j-core-2.25.4.jar</code>.</p>
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 9.4.0–9.8.1</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 9.4.0-9.8.1</p>
</div>
</header>
@@ -451,7 +451,7 @@ the Solr community considers this vulnerability
<strong>non-exploitable under st
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> < 9.8</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> ≤ 9.7</p>
</div>
</header>
@@ -475,7 +475,7 @@ the Solr community considers this vulnerability
<strong>non-exploitable under st
<strong>Status:</strong>
<span class="cdx-exploitable">exploitable</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> < 9.8.0</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> ≤ 9.7</p>
</div>
</header>
@@ -509,56 +509,19 @@ Users are also recommended to upgrade to Solr 9.8.0,
which mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> all</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> ≤ 9.5</p>
</div>
</header>
<h4>Description</h4>
<p>The only places we use json-path is for querying (via
Calcite) and for transforming/indexing custom JSON. Since the advisory
describes a problem that is limited to the current thread, and users that are
allowed to query/transform/index are already trusted to cause load to some
extent, this advisory does not appear to have impact on the way json-path is
used in Solr.</p>
+<p>Regardless, Solr upgraded the bundled json-path to 2.9.0 — which fixes
CVE-2023-51074 — in Solr 9.6.0, so the vulnerable json-path (≤ 2.8.0) only
shipped through Solr 9.5.</p>
<h4>References</h4>
<ul>
<li>CVE: <a
href="https://nvd.nist.gov/vuln/detail/CVE-2023-51074">CVE-2023-51074</a>, <a
href="https://github.com/advisories/GHSA-pfh2-hfmq-phg5">GHSA-pfh2-hfmq-phg5</a></li>
</ul>
</article>
- <article id="cve-velocity-tools" class="post panel radius">
- <header class="post-header">
- <h3 class="title">velocity-tools</h3>
- <div class="panel callout">
- <p class="subheader">
- <strong>Status:</strong>
- <span class="cdx-not-affected">not_affected</span>
- </p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 6.6.2-today</p>
- </div>
- </header>
-
- <h4>Description</h4>
- <p>Solr does not ship a Struts jar. This is a transitive POM
listing and not included with Solr (see comment in SOLR-2849).</p>
-
- <h4>References</h4>
- <ul>
- </ul>
- </article>
- <article id="cve-tika-core" class="post panel radius">
- <header class="post-header">
- <h3 class="title">tika-core.*</h3>
- <div class="panel callout">
- <p class="subheader">
- <strong>Status:</strong>
- <span class="cdx-not-affected">not_affected</span>
- </p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 7.3.1-today</p>
- </div>
- </header>
-
- <h4>Description</h4>
- <p>All Tika issues that could be Solr vulnerabilities would
only be exploitable if untrusted files are indexed with SolrCell. This is not
recommended in production systems, so Solr does not consider these valid CVEs
for Solr.</p>
-
- <h4>References</h4>
- <ul>
- </ul>
- </article>
<article id="cve-2022-42889" class="post panel radius">
<header class="post-header">
<h3 class="title"><a
href="https://nvd.nist.gov/vuln/detail/CVE-2022-42889">CVE-2022-42889</a>,
commons-text</h3>
@@ -567,7 +530,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which
mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> < 9.1</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> ≤ 9.0</p>
</div>
</header>
@@ -607,7 +570,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which
mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> < 9.1</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> ≤ 9.0</p>
</div>
</header>
@@ -627,7 +590,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which
mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> < 9.1</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> ≤ 9.0</p>
</div>
</header>
@@ -687,7 +650,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which
mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> to present</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> ≤ 8.x</p>
</div>
</header>
@@ -707,7 +670,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which
mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 7.3.0-present</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 7.3.0-8.x</p>
</div>
</header>
@@ -747,7 +710,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which
mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 8.1.0- today</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 8.1.0-8.x</p>
</div>
</header>
@@ -827,7 +790,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which
mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 4.x-today</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 4.x-9.1</p>
</div>
</header>
@@ -887,7 +850,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which
mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 5.4.0-today</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 5.4.0-8.x</p>
</div>
</header>
@@ -907,7 +870,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which
mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 4.6.0-today</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 4.6.0-8.x</p>
</div>
</header>
@@ -927,7 +890,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which
mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 4.6.0-today</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 4.6.0-8.x</p>
</div>
</header>
@@ -987,7 +950,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which
mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 4.7.0-today</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 4.7.0-8.x</p>
</div>
</header>
@@ -1027,7 +990,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which
mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 5.2.0-today</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 5.2.0-8.x</p>
</div>
</header>
@@ -1047,18 +1010,42 @@ Users are also recommended to upgrade to Solr 9.8.0,
which mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 5.5.5, 6.2.0-today</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 5.5.5, 6.2.0-9.10</p>
</div>
</header>
<h4>Description</h4>
<p>See https://github.com/Gagravarr/VorbisJava/issues/30;
reported CVEs are not related to OggVorbis at all.</p>
+<p>Tika as an in-process component was removed in Solr 9.11.</p>
<h4>References</h4>
<ul>
<li>CVE: <a
href="https://nvd.nist.gov/vuln/detail/CVE-2016-6809">CVE-2016-6809</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1335">CVE-2018-1335</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1338">CVE-2018-1338</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1339">CVE-2018-1339</a></li>
</ul>
</article>
+ <article id="cve-2016-1181" class="post panel radius">
+ <header class="post-header">
+ <h3 class="title"><a
href="https://nvd.nist.gov/vuln/detail/CVE-2015-0899">CVE-2015-0899</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2016-1181">CVE-2016-1181</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2016-1182">CVE-2016-1182</a>, Apache
Struts 1 CVEs via velocity-tools transitive dependency</h3>
+ <div class="panel callout">
+ <p class="subheader">
+ <strong>Status:</strong>
+ <span class="cdx-not-affected">not_affected</span>
+ </p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 6.6.2-8.x</p>
+ </div>
+ </header>
+
+ <h4>Description</h4>
+ <p>Scanners flag <code>velocity-tools-2.0.jar</code> with
Apache Struts 1 CVEs because its POM declares a
+transitive dependency on <code>struts-core</code>, <code>struts-taglib</code>
and <code>struts-tiles</code> 1.3.8. Solr does not
+ship any Struts jar — the dependency is excluded and only appears as a
transitive POM listing
+(see SOLR-2849) — so these Struts vulnerabilities are not present in, or
exploitable through, Solr.</p>
+
+ <h4>References</h4>
+ <ul>
+ <li>CVE: <a
href="https://nvd.nist.gov/vuln/detail/CVE-2015-0899">CVE-2015-0899</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2016-1181">CVE-2016-1181</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2016-1182">CVE-2016-1182</a></li>
+ </ul>
+ </article>
<article id="cve-2015-5237" class="post panel radius">
<header class="post-header">
<h3 class="title"><a
href="https://nvd.nist.gov/vuln/detail/CVE-2015-5237">CVE-2015-5237</a>,
protobuf-java</h3>
@@ -1067,7 +1054,7 @@ Users are also recommended to upgrade to Solr 9.8.0,
which mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 6.5.0-today</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 6.5.0-7.x</p>
</div>
</header>
@@ -1127,7 +1114,7 @@ Users are also recommended to upgrade to Solr 9.8.0,
which mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 4.6.0-today</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 4.6.0-7.x</p>
</div>
</header>
@@ -1147,7 +1134,7 @@ Users are also recommended to upgrade to Solr 9.8.0,
which mitigates this issue
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> ~2.9-today</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 2.9-9.10</p>
</div>
</header>