This is an automated email from the ASF dual-hosted git repository.

github-actions[bot] pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/solr-site.git


The following commit(s) were added to refs/heads/asf-staging by this push:
     new b7f9740a8 Commit build products
b7f9740a8 is described below

commit b7f9740a8fb16030cf0b8052ab83aa462e034523
Author: Build Pelican (action) <[email protected]>
AuthorDate: Sun Jun 21 18:47:33 2026 +0000

    Commit build products
---
 output/feeds/all.atom.xml            |  31 +++++-
 output/feeds/solr/vex.atom.xml       |  10 +-
 output/security-dependency-cves.html |  65 +++++-------
 output/solr.vex.json                 | 200 ++++++++++++++++++++++-------------
 output/vex.html                      | 103 ++++++++----------
 5 files changed, 234 insertions(+), 175 deletions(-)

diff --git a/output/feeds/all.atom.xml b/output/feeds/all.atom.xml
index 9a1400f02..d9c1aadd6 100644
--- a/output/feeds/all.atom.xml
+++ b/output/feeds/all.atom.xml
@@ -939,7 +939,8 @@ Therefore, Solr Clouds with Authorization setup will only 
be vulnerable via user
 Users are recommended to upgrade to version 9.3.0 or later, in which 
environment variables are not published via the Metrics API.&lt;/p&gt;
 &lt;p&gt;&lt;strong&gt;References:&lt;/strong&gt;&lt;br&gt;
 JIRA - &lt;a 
href="https://issues.apache.org/jira/browse/SOLR-16808"&gt;SOLR-15233&lt;/a&gt;&lt;br&gt;
-CVE - &lt;a 
href="https://nvd.nist.gov/vuln/detail/CVE-2023-50290"&gt;CVE-2023-50290&lt;/a&gt;&lt;/p&gt;</content><category
 term="solr/security"/></entry><entry><title>json-path</title><link 
href="/cve-2023-51074.html" 
rel="alternate"/><published>2024-01-12T00:00:00+00:00</published><updated>2024-01-12T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2024-01-12:/cve-2023-51074.html</id><summary
 type="html">&lt;p&gt;The only places we use json-path is for  [...]
+CVE - &lt;a 
href="https://nvd.nist.gov/vuln/detail/CVE-2023-50290"&gt;CVE-2023-50290&lt;/a&gt;&lt;/p&gt;</content><category
 term="solr/security"/></entry><entry><title>json-path</title><link 
href="/cve-2023-51074.html" 
rel="alternate"/><published>2024-01-12T00:00:00+00:00</published><updated>2024-01-12T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2024-01-12:/cve-2023-51074.html</id><summary
 type="html">&lt;p&gt;The only places we use json-path is for  [...]
+&lt;p&gt;Regardless, Solr upgraded the bundled json-path to 2.9.0 — which 
fixes CVE-2023-51074 — in Solr 9.6.0, so the vulnerable json-path (≤ 2.8.0) 
only shipped through Solr 9.5.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache Solr Operator™ v0.8.0 
available</title><link href="/apache-solr-operatortm-v080-available.html" 
rel="alternate"/><published>2023-10-20T00:00:00+00:00</published><updated>2023-10-20T00:00:00+00:00</updated><author><name>Solr
 Developers</ [...]
 &lt;p&gt;The Apache Solr Operator is a safe and easy way of managing a Solr 
ecosystem in Kubernetes.&lt;/p&gt;
 &lt;p&gt;This release contains numerous bug fixes, optimizations, and 
improvements, some of which are highlighted below …&lt;/p&gt;</summary><content 
type="html">&lt;p&gt;The Apache Solr PMC is pleased to announce the release of 
the Apache Solr Operator v0.8.0.&lt;/p&gt;
 &lt;p&gt;The Apache Solr Operator is a safe and easy way of managing a Solr 
ecosystem in Kubernetes.&lt;/p&gt;
@@ -1131,7 +1132,14 @@ CVE - &lt;a 
href="https://nvd.nist.gov/vuln/detail/CVE-2023-50290"&gt;CVE-2023-5
 &lt;p&gt;Please refer to the Upgrade Notes in the Solr Ref Guide for 
information on upgrading from previous Solr versions:&lt;/p&gt;
 &lt;p&gt;&lt;a 
href="https://solr.apache.org/guide/solr/9_1/upgrade-notes/solr-upgrade-notes.html"&gt;https://solr.apache.org/guide/solr/9_1/upgrade-notes/solr-upgrade-notes.html&lt;/a&gt;&lt;/p&gt;
 &lt;p&gt;Please read CHANGES.txt for a full list of bugfixes:&lt;/p&gt;
-&lt;p&gt;&lt;a 
href="https://solr.apache.org/9_1_1/changes/Changes.html"&gt;https://solr.apache.org/9_1_1/changes/Changes.html&lt;/a&gt;&lt;/p&gt;</content><category
 term="solr/news"/></entry><entry><title>xercesImpl</title><link 
href="/cve-2012-0881.html" 
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2022-12-14:/cve-2012-0881.html</id><content
 type="html">&lt;p&gt;Onl [...]
+&lt;p&gt;&lt;a 
href="https://solr.apache.org/9_1_1/changes/Changes.html"&gt;https://solr.apache.org/9_1_1/changes/Changes.html&lt;/a&gt;&lt;/p&gt;</content><category
 term="solr/news"/></entry><entry><title>xercesImpl</title><link 
href="/cve-2012-0881.html" 
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2022-12-14:/cve-2012-0881.html</id><content
 type="html">&lt;p&gt;Onl [...]
+transitive dependency on &lt;code&gt;struts-core&lt;/code&gt;, 
&lt;code&gt;struts-taglib&lt;/code&gt; and 
&lt;code&gt;struts-tiles&lt;/code&gt; 1.3.8. Solr does not
+ship any Struts jar — the dependency is excluded and only appears as a 
transitive POM listing
+(see SOLR-2849) — so these Struts vulnerabilities 
…&lt;/p&gt;</summary><content type="html">&lt;p&gt;Scanners flag 
&lt;code&gt;velocity-tools-2.0.jar&lt;/code&gt; with Apache Struts 1 CVEs 
because its POM declares a
+transitive dependency on &lt;code&gt;struts-core&lt;/code&gt;, 
&lt;code&gt;struts-taglib&lt;/code&gt; and 
&lt;code&gt;struts-tiles&lt;/code&gt; 1.3.8. Solr does not
+ship any Struts jar — the dependency is excluded and only appears as a 
transitive POM listing
+(see SOLR-2849) — so these Struts vulnerabilities are not present in, or 
exploitable through, Solr.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>vorbis-java-tika</title><link 
href="/cve-2016-6809.html" 
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2022-12-14:/cve-2016-6809.html</id><content
 type="html">&lt;p&gt;See https://github.com/Gagravarr/Vo [...]
+&lt;p&gt;Tika as an in-process component was removed in Solr 
9.11.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>org.restlet</title><link 
href="/cve-2017-14868.html" 
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2022-12-14:/cve-2017-14868.html</id><content
 type="html">&lt;p&gt;Solr should not be exposed outside a firewall where bad 
actors can send [...]
 Solr 6.5 to 8.11.2
 Solr 9.0&lt;/p&gt;
 &lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br&gt;
@@ -1558,4 +1566,21 @@ See &lt;a 
href="https://lists.apache.org/thread/kgh63sncrsm2bls884pg87mnt8vqztmz
 &lt;p&gt;A summary of important changes is published in the documentation 
at:&lt;/p&gt;
 &lt;p&gt;&lt;a 
href="https://apache.github.io/solr-operator/docs/upgrade-notes.html"&gt;https://apache.github.io/solr-operator/docs/upgrade-notes.html&lt;/a&gt;&lt;/p&gt;
 &lt;p&gt;For the most exhaustive list, see the full release notes in the 
Github Releases or by viewing the git history in the solr-operator 
repo.&lt;/p&gt;
-&lt;p&gt;&lt;a 
href="https://github.com/apache/solr-operator/releases/tag/v0.3.0"&gt;https://github.com/apache/solr-operator/releases/tag/v0.3.0&lt;/a&gt;&lt;/p&gt;</content><category
 term="solr/operator/news"/></entry></feed>
\ No newline at end of file
+&lt;p&gt;&lt;a 
href="https://github.com/apache/solr-operator/releases/tag/v0.3.0"&gt;https://github.com/apache/solr-operator/releases/tag/v0.3.0&lt;/a&gt;&lt;/p&gt;</content><category
 term="solr/operator/news"/></entry><entry><title>Apache Solr™ 8.8.2 
available</title><link href="/apache-solrtm-882-available.html" 
rel="alternate"/><published>2021-04-12T00:00:00+00:00</published><updated>2021-04-12T00:00:00+00:00</updated><author><name>Solr
 Developers</name></author><id>tag:None,2021-04-1 [...]
+&lt;p&gt;Solr is the popular, blazing fast, open source NoSQL search platform 
from the Apache Lucene project. Its major features include powerful full-text 
search, hit highlighting, faceted search, dynamic clustering, database 
integration, rich document handling, and …&lt;/p&gt;</summary><content 
type="html">&lt;p&gt;The Solr PMC is pleased to announce the release of Apache 
Solr 8.8.2.&lt;/p&gt;
+&lt;p&gt;Solr is the popular, blazing fast, open source NoSQL search platform 
from the Apache Lucene project. Its major features include powerful full-text 
search, hit highlighting, faceted search, dynamic clustering, database 
integration, rich document handling, and geospatial search. Solr is highly 
scalable, providing fault tolerant distributed search and indexing, and powers 
the search and navigation features of many of the world's largest internet 
sites.&lt;/p&gt;
+&lt;p&gt;Solr 8.8.2 is available for immediate download at:&lt;/p&gt;
+&lt;p&gt;&lt;a 
href="https://solr.apache.org/downloads.html"&gt;https://solr.apache.org/downloads.html&lt;/a&gt;&lt;/p&gt;
+&lt;h3 id="solr-882-release-highlights"&gt;Solr 8.8.2 Release Highlights:&lt;a 
class="headerlink" href="#solr-882-release-highlights" title="Permanent 
link"&gt;&amp;para;&lt;/a&gt;&lt;/h3&gt;
+&lt;ul&gt;
+&lt;li&gt;SOLR-15249: Properly set ZK ACLs on /security.json&lt;/li&gt;
+&lt;li&gt;SOLR-15233: Set doAs param in 
ConfigurableInternodeAuthHadoopPlugin&lt;/li&gt;
+&lt;li&gt;SOLR-15217: Use shardsWhitelist in ReplicationHandler&lt;/li&gt;
+&lt;li&gt;SOLR-15288: Hardening NODEDOWN event in collections using 
PerReplicaStates&lt;/li&gt;
+&lt;/ul&gt;
+&lt;p&gt;Please refer to the Upgrade Notes in the Solr Ref Guide for 
information on upgrading from previous Solr versions:&lt;/p&gt;
+&lt;p&gt;&lt;a 
href="https://solr.apache.org/guide/8_8/solr-upgrade-notes.html"&gt;https://solr.apache.org/guide/8_8/solr-upgrade-notes.html&lt;/a&gt;&lt;/p&gt;
+&lt;p&gt;Please read CHANGES.txt for a full list of bugfixes:&lt;/p&gt;
+&lt;p&gt;&lt;a 
href="https://solr.apache.org/8_8_2/changes/Changes.html"&gt;https://solr.apache.org/8_8_2/changes/Changes.html&lt;/a&gt;&lt;/p&gt;
+&lt;p&gt;Solr 8.8.2 also includes bugfixes in the corresponding Apache Lucene 
release:&lt;/p&gt;
+&lt;p&gt;&lt;a 
href="https://lucene.apache.org/core/8_8_2/changes/Changes.html"&gt;https://lucene.apache.org/core/8_8_2/changes/Changes.html&lt;/a&gt;&lt;/p&gt;</content><category
 term="solr/news"/></entry></feed>
\ No newline at end of file
diff --git a/output/feeds/solr/vex.atom.xml b/output/feeds/solr/vex.atom.xml
index 8bf259b38..15ca522e1 100644
--- a/output/feeds/solr/vex.atom.xml
+++ b/output/feeds/solr/vex.atom.xml
@@ -175,4 +175,12 @@ These replacements are incorrectly treated as "trusted" 
and can leverage &lt;cod
 &lt;p&gt;Users can protect against the vulnerability by enabling 
authentication and authorization on their Solr clusters or switching to 
SolrCloud (and away from "FileSystemConfigSetService").
 Users are also recommended to upgrade to Solr 9.8.0, which mitigates this 
issue by disabling use of "&lt;lib&gt;" tags by default.&lt;/p&gt;
 &lt;h4 id="credit"&gt;Credit&lt;a class="headerlink" href="#credit" 
title="Permanent link"&gt;&amp;para;&lt;/a&gt;&lt;/h4&gt;
-&lt;p&gt;pwn null (reporter)&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>json-path</title><link 
href="/cve-2023-51074.html" 
rel="alternate"/><published>2024-01-12T00:00:00+00:00</published><updated>2024-01-12T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2024-01-12:/cve-2023-51074.html</id><summary
 type="html">&lt;p&gt;The only places we use json-path is for querying (via 
Calcite) and for transforming/indexing custom JSON. Since [...]
\ No newline at end of file
+&lt;p&gt;pwn null (reporter)&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>json-path</title><link 
href="/cve-2023-51074.html" 
rel="alternate"/><published>2024-01-12T00:00:00+00:00</published><updated>2024-01-12T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2024-01-12:/cve-2023-51074.html</id><summary
 type="html">&lt;p&gt;The only places we use json-path is for querying (via 
Calcite) and for transforming/indexing custom JSON. Since [...]
+&lt;p&gt;Regardless, Solr upgraded the bundled json-path to 2.9.0 — which 
fixes CVE-2023-51074 — in Solr 9.6.0, so the vulnerable json-path (≤ 2.8.0) 
only shipped through Solr 9.5.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>xercesImpl</title><link 
href="/cve-2012-0881.html" 
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
 Developers</name></author><id>tag:None,2022-12-14:/cve-2012-0881 [...]
+transitive dependency on &lt;code&gt;struts-core&lt;/code&gt;, 
&lt;code&gt;struts-taglib&lt;/code&gt; and 
&lt;code&gt;struts-tiles&lt;/code&gt; 1.3.8. Solr does not
+ship any Struts jar — the dependency is excluded and only appears as a 
transitive POM listing
+(see SOLR-2849) — so these Struts vulnerabilities 
…&lt;/p&gt;</summary><content type="html">&lt;p&gt;Scanners flag 
&lt;code&gt;velocity-tools-2.0.jar&lt;/code&gt; with Apache Struts 1 CVEs 
because its POM declares a
+transitive dependency on &lt;code&gt;struts-core&lt;/code&gt;, 
&lt;code&gt;struts-taglib&lt;/code&gt; and 
&lt;code&gt;struts-tiles&lt;/code&gt; 1.3.8. Solr does not
+ship any Struts jar — the dependency is excluded and only appears as a 
transitive POM listing
+(see SOLR-2849) — so these Struts vulnerabilities are not present in, or 
exploitable through, Solr.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>vorbis-java-tika</title><link 
href="/cve-2016-6809.html" 
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2022-12-14:/cve-2016-6809.html</id><content
 type="html">&lt;p&gt;See https://github.com/Gagravarr/Vo [...]
+&lt;p&gt;Tika as an in-process component was removed in Solr 
9.11.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>org.restlet</title><link 
href="/cve-2017-14868.html" 
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2022-12-14:/cve-2017-14868.html</id><content
 type="html">&lt;p&gt;Solr should not be exposed outside a firewall where bad 
actors can send [...]
\ No newline at end of file
diff --git a/output/security-dependency-cves.html 
b/output/security-dependency-cves.html
index e5f23c9b2..a96bb706e 100644
--- a/output/security-dependency-cves.html
+++ b/output/security-dependency-cves.html
@@ -223,7 +223,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51504";>CVE-2024-51504</a>   
   </td>
-      <td>9.4.0–9.8.1</td>
+      <td>9.4.0-9.8.1</td>
       <td>
           zookeeper-3.9.0.jar,           zookeeper-3.9.1.jar,           
zookeeper-3.9.2.jar      </td>
       <td>not affected</td>
@@ -232,7 +232,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6763";>CVE-2024-6763</a>     
 </td>
-      <td>< 9.8</td>
+      <td>≤ 9.7</td>
       <td>
           jetty-http-10.0.22.jar      </td>
       <td>not affected</td>
@@ -241,7 +241,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51074";>CVE-2023-51074</a>, 
<a 
href="https://github.com/advisories/GHSA-pfh2-hfmq-phg5";>GHSA-pfh2-hfmq-phg5</a>
      </td>
-      <td>all</td>
+      <td>≤ 9.5</td>
       <td>
           json-path-2.8.0.jar      </td>
       <td>not affected</td>
@@ -249,26 +249,8 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     </tr>
     <tr>
       <td>
-      </td>
-      <td>6.6.2-today</td>
-      <td>
-          velocity-tools-2.0.jar      </td>
-      <td>not affected</td>
-      <td><a href="/vex.html#cve-velocity-tools">velocity-tools</a></td>
-    </tr>
-    <tr>
-      <td>
-      </td>
-      <td>7.3.1-today</td>
-      <td>
-          tika-core.*.jar      </td>
-      <td>not affected</td>
-      <td><a href="/vex.html#cve-tika-core">tika-core.*</a></td>
-    </tr>
-    <tr>
-      <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42889";>CVE-2022-42889</a>   
   </td>
-      <td>< 9.1</td>
+      <td>≤ 9.0</td>
       <td>
           commons-text-1.9.jar      </td>
       <td>not affected</td>
@@ -277,7 +259,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33980";>CVE-2022-33980</a>   
   </td>
-      <td>< 9.1</td>
+      <td>≤ 9.0</td>
       <td>
           commons-configuration2-2.7.jar      </td>
       <td>not affected</td>
@@ -286,7 +268,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25168";>CVE-2022-25168</a>   
   </td>
-      <td>< 9.1</td>
+      <td>≤ 9.0</td>
       <td>
           hadoop-common-3.2.2.jar      </td>
       <td>not affected</td>
@@ -313,7 +295,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33813";>CVE-2021-33813</a>   
   </td>
-      <td>to present</td>
+      <td>≤ 8.x</td>
       <td>
           jdom-*.jar      </td>
       <td>not affected</td>
@@ -322,7 +304,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27223";>CVE-2020-27223</a>   
   </td>
-      <td>7.3.0-present</td>
+      <td>7.3.0-8.x</td>
       <td>
           jetty-9.4.6 to 9.4.36      </td>
       <td>not affected</td>
@@ -340,7 +322,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13955";>CVE-2020-13955</a>   
   </td>
-      <td>8.1.0- today</td>
+      <td>8.1.0-8.x</td>
       <td>
           avatica-core-1.13.0.jar,           calcite-core-1.18.0.jar      </td>
       <td>not affected</td>
@@ -376,7 +358,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-8088";>CVE-2018-8088</a>     
 </td>
-      <td>4.x-today</td>
+      <td>4.x-9.1</td>
       <td>
           slf4j-api-1.7.24.jar,           jcl-over-slf4j-1.7.24.jar,           
jul-to-slf4j-1.7.24.jar      </td>
       <td>not affected</td>
@@ -403,7 +385,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10237";>CVE-2018-10237</a>   
   </td>
-      <td>5.4.0-today</td>
+      <td>5.4.0-8.x</td>
       <td>
           carrot2-guava-18.0.jar      </td>
       <td>not affected</td>
@@ -412,7 +394,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10237";>CVE-2018-10237</a>   
   </td>
-      <td>4.6.0-today</td>
+      <td>4.6.0-8.x</td>
       <td>
           guava-*.jar      </td>
       <td>not affected</td>
@@ -421,7 +403,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000632";>CVE-2018-1000632</a>   
   </td>
-      <td>4.6.0-today</td>
+      <td>4.6.0-8.x</td>
       <td>
           dom4j-1.6.1.jar      </td>
       <td>not affected</td>
@@ -448,7 +430,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15095";>CVE-2017-15095</a>, 
<a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17485";>CVE-2017-17485</a>, 
<a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7525";>CVE-2017-7525</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2018-5968";>CVE-2018-5968</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2018-7489";>CVE-2018-7489</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2019-12086";>CVE-2019-12086</a>, <a 
href="https://nvd.nist.gov/ [...]
-      <td>4.7.0-today</td>
+      <td>4.7.0-8.x</td>
       <td>
           jackson-databind-*.jar      </td>
       <td>not affected</td>
@@ -466,7 +448,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14868";>CVE-2017-14868</a>, 
<a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14949";>CVE-2017-14949</a>    
  </td>
-      <td>5.2.0-today</td>
+      <td>5.2.0-8.x</td>
       <td>
           org.restlet-2.3.0.jar      </td>
       <td>not affected</td>
@@ -475,7 +457,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6809";>CVE-2016-6809</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1335";>CVE-2018-1335</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1338";>CVE-2018-1338</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1339";>CVE-2018-1339</a>      
</td>
-      <td>5.5.5, 6.2.0-today</td>
+      <td>5.5.5, 6.2.0-9.10</td>
       <td>
           vorbis-java-tika-0.8.jar      </td>
       <td>not affected</td>
@@ -483,8 +465,17 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     </tr>
     <tr>
       <td>
+<a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0899";>CVE-2015-0899</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2016-1181";>CVE-2016-1181</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2016-1182";>CVE-2016-1182</a>      
</td>
+      <td>6.6.2-8.x</td>
+      <td>
+          velocity-tools-2.0.jar      </td>
+      <td>not affected</td>
+      <td><a href="/vex.html#cve-2016-1181">Apache Struts 1 CVEs via 
velocity-tools transitive dependency</a></td>
+    </tr>
+    <tr>
+      <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5237";>CVE-2015-5237</a>     
 </td>
-      <td>6.5.0-today</td>
+      <td>6.5.0-7.x</td>
       <td>
           protobuf-java-3.1.0.jar      </td>
       <td>not affected</td>
@@ -511,7 +502,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2098";>CVE-2012-2098</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1324";>CVE-2018-1324</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2018-11771";>CVE-2018-11771</a>      
</td>
-      <td>4.6.0-today</td>
+      <td>4.6.0-7.x</td>
       <td>
           commons-compress (only as part of Ant 1.8.2)      </td>
       <td>not affected</td>
@@ -520,7 +511,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0881";>CVE-2012-0881</a>     
 </td>
-      <td>~2.9-today</td>
+      <td>2.9-9.10</td>
       <td>
           xercesImpl-2.9.1.jar      </td>
       <td>not affected</td>
diff --git a/output/solr.vex.json b/output/solr.vex.json
index 496b4dbfc..fc3be49c6 100644
--- a/output/solr.vex.json
+++ b/output/solr.vex.json
@@ -7,7 +7,7 @@
       "name": "solr",
       "version": "SNAPSHOT",
       "type": "application",
-      "bom-ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+      "bom-ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
     }
   },
   "vulnerabilities": [
@@ -23,7 +23,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -39,7 +39,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -55,7 +55,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -71,7 +71,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -87,7 +87,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -103,7 +103,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -119,7 +119,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -135,7 +135,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -151,7 +151,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -167,7 +167,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -183,7 +183,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -199,7 +199,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -215,7 +215,55 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
+        }
+      ]
+    },
+    {
+      "id": "CVE-2015-0899",
+      "source": {
+        "name": "NVD",
+        "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-0899";
+      },
+      "analysis": {
+        "state": "not_affected",
+        "detail": "Scanners flag `velocity-tools-2.0.jar` with Apache Struts 1 
CVEs because its POM declares a\ntransitive dependency on `struts-core`, 
`struts-taglib` and `struts-tiles` 1.3.8. Solr does not\nship any Struts jar 
\u2014 the dependency is excluded and only appears as a transitive POM 
listing\n(see SOLR-2849) \u2014 so these Struts vulnerabilities are not present 
in, or exploitable through, Solr."
+      },
+      "affects": [
+        {
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
+        }
+      ]
+    },
+    {
+      "id": "CVE-2016-1181",
+      "source": {
+        "name": "NVD",
+        "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-1181";
+      },
+      "analysis": {
+        "state": "not_affected",
+        "detail": "Scanners flag `velocity-tools-2.0.jar` with Apache Struts 1 
CVEs because its POM declares a\ntransitive dependency on `struts-core`, 
`struts-taglib` and `struts-tiles` 1.3.8. Solr does not\nship any Struts jar 
\u2014 the dependency is excluded and only appears as a transitive POM 
listing\n(see SOLR-2849) \u2014 so these Struts vulnerabilities are not present 
in, or exploitable through, Solr."
+      },
+      "affects": [
+        {
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
+        }
+      ]
+    },
+    {
+      "id": "CVE-2016-1182",
+      "source": {
+        "name": "NVD",
+        "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-1182";
+      },
+      "analysis": {
+        "state": "not_affected",
+        "detail": "Scanners flag `velocity-tools-2.0.jar` with Apache Struts 1 
CVEs because its POM declares a\ntransitive dependency on `struts-core`, 
`struts-taglib` and `struts-tiles` 1.3.8. Solr does not\nship any Struts jar 
\u2014 the dependency is excluded and only appears as a transitive POM 
listing\n(see SOLR-2849) \u2014 so these Struts vulnerabilities are not present 
in, or exploitable through, Solr."
+      },
+      "affects": [
+        {
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -227,11 +275,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30; 
reported CVEs are not related to OggVorbis at all."
+        "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30; 
reported CVEs are not related to OggVorbis at all.\n\nTika as an in-process 
component was removed in Solr 9.11."
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -243,11 +291,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30; 
reported CVEs are not related to OggVorbis at all."
+        "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30; 
reported CVEs are not related to OggVorbis at all.\n\nTika as an in-process 
component was removed in Solr 9.11."
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -259,11 +307,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30; 
reported CVEs are not related to OggVorbis at all."
+        "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30; 
reported CVEs are not related to OggVorbis at all.\n\nTika as an in-process 
component was removed in Solr 9.11."
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -275,11 +323,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30; 
reported CVEs are not related to OggVorbis at all."
+        "detail": "See https://github.com/Gagravarr/VorbisJava/issues/30; 
reported CVEs are not related to OggVorbis at all.\n\nTika as an in-process 
component was removed in Solr 9.11."
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -295,7 +343,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -311,7 +359,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -327,7 +375,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -343,7 +391,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -359,7 +407,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -375,7 +423,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -391,7 +439,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -407,7 +455,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -423,7 +471,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -439,7 +487,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -455,7 +503,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -471,7 +519,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -487,7 +535,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -503,7 +551,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -519,7 +567,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -535,7 +583,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -551,7 +599,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -567,7 +615,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -583,7 +631,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -599,7 +647,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -615,7 +663,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -631,7 +679,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -647,7 +695,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -663,7 +711,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -679,7 +727,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -695,7 +743,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -711,7 +759,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -727,7 +775,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -743,7 +791,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -759,7 +807,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -775,7 +823,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -791,7 +839,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -807,7 +855,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -823,7 +871,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -839,7 +887,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -855,7 +903,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -871,7 +919,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -887,7 +935,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -903,7 +951,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -922,7 +970,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -938,7 +986,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -950,11 +998,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "The only places we use json-path is for querying (via 
Calcite) and for transforming/indexing custom JSON. Since the advisory 
describes a problem that is limited to the current thread, and users that are 
allowed to query/transform/index are already trusted to cause load to some 
extent, this advisory does not appear to have impact on the way json-path is 
used in Solr."
+        "detail": "The only places we use json-path is for querying (via 
Calcite) and for transforming/indexing custom JSON. Since the advisory 
describes a problem that is limited to the current thread, and users that are 
allowed to query/transform/index are already trusted to cause load to some 
extent, this advisory does not appear to have impact on the way json-path is 
used in Solr.\n\nRegardless, Solr upgraded the bundled json-path to 2.9.0 
\u2014 which fixes CVE-2023-51074 \u2014 in  [...]
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -966,11 +1014,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "The only places we use json-path is for querying (via 
Calcite) and for transforming/indexing custom JSON. Since the advisory 
describes a problem that is limited to the current thread, and users that are 
allowed to query/transform/index are already trusted to cause load to some 
extent, this advisory does not appear to have impact on the way json-path is 
used in Solr."
+        "detail": "The only places we use json-path is for querying (via 
Calcite) and for transforming/indexing custom JSON. Since the advisory 
describes a problem that is limited to the current thread, and users that are 
allowed to query/transform/index are already trusted to cause load to some 
extent, this advisory does not appear to have impact on the way json-path is 
used in Solr.\n\nRegardless, Solr upgraded the bundled json-path to 2.9.0 
\u2014 which fixes CVE-2023-51074 \u2014 in  [...]
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -989,7 +1037,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -1005,7 +1053,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -1022,7 +1070,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -1038,7 +1086,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -1055,7 +1103,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -1072,7 +1120,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -1089,7 +1137,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -1106,7 +1154,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     },
@@ -1123,7 +1171,7 @@
       },
       "affects": [
         {
-          "ref": "533b70ab-7b8b-53a5-b9e1-e829e7017b67"
+          "ref": "5236b97f-6aa9-5b4c-91b4-400c65345c60"
         }
       ]
     }
diff --git a/output/vex.html b/output/vex.html
index f272f9da7..a350724fd 100644
--- a/output/vex.html
+++ b/output/vex.html
@@ -415,7 +415,7 @@ with <code>log4j-core-2.25.4.jar</code>.</p>
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 9.4.0–9.8.1</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 9.4.0-9.8.1</p>
                     </div>
                 </header>
 
@@ -451,7 +451,7 @@ the Solr community considers this vulnerability 
<strong>non-exploitable under st
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> < 9.8</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> ≤ 9.7</p>
                     </div>
                 </header>
 
@@ -475,7 +475,7 @@ the Solr community considers this vulnerability 
<strong>non-exploitable under st
                             <strong>Status:</strong>
                             <span class="cdx-exploitable">exploitable</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> < 9.8.0</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> ≤ 9.7</p>
                     </div>
                 </header>
 
@@ -509,56 +509,19 @@ Users are also recommended to upgrade to Solr 9.8.0, 
which mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> all</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> ≤ 9.5</p>
                     </div>
                 </header>
 
                 <h4>Description</h4>
                 <p>The only places we use json-path is for querying (via 
Calcite) and for transforming/indexing custom JSON. Since the advisory 
describes a problem that is limited to the current thread, and users that are 
allowed to query/transform/index are already trusted to cause load to some 
extent, this advisory does not appear to have impact on the way json-path is 
used in Solr.</p>
+<p>Regardless, Solr upgraded the bundled json-path to 2.9.0 — which fixes 
CVE-2023-51074 — in Solr 9.6.0, so the vulnerable json-path (≤ 2.8.0) only 
shipped through Solr 9.5.</p>
 
                 <h4>References</h4>
                 <ul>
                         <li>CVE: <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2023-51074";>CVE-2023-51074</a>, <a 
href="https://github.com/advisories/GHSA-pfh2-hfmq-phg5";>GHSA-pfh2-hfmq-phg5</a></li>
                 </ul>
             </article>
-            <article id="cve-velocity-tools" class="post panel radius">
-                <header class="post-header">
-                    <h3 class="title">velocity-tools</h3>
-                    <div class="panel callout">
-                        <p class="subheader">
-                            <strong>Status:</strong>
-                            <span class="cdx-not-affected">not_affected</span>
-                        </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 6.6.2-today</p>
-                    </div>
-                </header>
-
-                <h4>Description</h4>
-                <p>Solr does not ship a Struts jar. This is a transitive POM 
listing and not included with Solr (see comment in SOLR-2849).</p>
-
-                <h4>References</h4>
-                <ul>
-                </ul>
-            </article>
-            <article id="cve-tika-core" class="post panel radius">
-                <header class="post-header">
-                    <h3 class="title">tika-core.*</h3>
-                    <div class="panel callout">
-                        <p class="subheader">
-                            <strong>Status:</strong>
-                            <span class="cdx-not-affected">not_affected</span>
-                        </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 7.3.1-today</p>
-                    </div>
-                </header>
-
-                <h4>Description</h4>
-                <p>All Tika issues that could be Solr vulnerabilities would 
only be exploitable if untrusted files are indexed with SolrCell. This is not 
recommended in production systems, so Solr does not consider these valid CVEs 
for Solr.</p>
-
-                <h4>References</h4>
-                <ul>
-                </ul>
-            </article>
             <article id="cve-2022-42889" class="post panel radius">
                 <header class="post-header">
                     <h3 class="title"><a 
href="https://nvd.nist.gov/vuln/detail/CVE-2022-42889";>CVE-2022-42889</a>, 
commons-text</h3>
@@ -567,7 +530,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which 
mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> < 9.1</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> ≤ 9.0</p>
                     </div>
                 </header>
 
@@ -607,7 +570,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which 
mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> < 9.1</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> ≤ 9.0</p>
                     </div>
                 </header>
 
@@ -627,7 +590,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which 
mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> < 9.1</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> ≤ 9.0</p>
                     </div>
                 </header>
 
@@ -687,7 +650,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which 
mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> to present</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> ≤ 8.x</p>
                     </div>
                 </header>
 
@@ -707,7 +670,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which 
mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 7.3.0-present</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 7.3.0-8.x</p>
                     </div>
                 </header>
 
@@ -747,7 +710,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which 
mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 8.1.0- today</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 8.1.0-8.x</p>
                     </div>
                 </header>
 
@@ -827,7 +790,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which 
mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 4.x-today</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 4.x-9.1</p>
                     </div>
                 </header>
 
@@ -887,7 +850,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which 
mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 5.4.0-today</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 5.4.0-8.x</p>
                     </div>
                 </header>
 
@@ -907,7 +870,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which 
mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 4.6.0-today</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 4.6.0-8.x</p>
                     </div>
                 </header>
 
@@ -927,7 +890,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which 
mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 4.6.0-today</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 4.6.0-8.x</p>
                     </div>
                 </header>
 
@@ -987,7 +950,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which 
mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 4.7.0-today</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 4.7.0-8.x</p>
                     </div>
                 </header>
 
@@ -1027,7 +990,7 @@ Users are also recommended to upgrade to Solr 9.8.0, which 
mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 5.2.0-today</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 5.2.0-8.x</p>
                     </div>
                 </header>
 
@@ -1047,18 +1010,42 @@ Users are also recommended to upgrade to Solr 9.8.0, 
which mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 5.5.5, 6.2.0-today</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 5.5.5, 6.2.0-9.10</p>
                     </div>
                 </header>
 
                 <h4>Description</h4>
                 <p>See https://github.com/Gagravarr/VorbisJava/issues/30; 
reported CVEs are not related to OggVorbis at all.</p>
+<p>Tika as an in-process component was removed in Solr 9.11.</p>
 
                 <h4>References</h4>
                 <ul>
                         <li>CVE: <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2016-6809";>CVE-2016-6809</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1335";>CVE-2018-1335</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1338";>CVE-2018-1338</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2018-1339";>CVE-2018-1339</a></li>
                 </ul>
             </article>
+            <article id="cve-2016-1181" class="post panel radius">
+                <header class="post-header">
+                    <h3 class="title"><a 
href="https://nvd.nist.gov/vuln/detail/CVE-2015-0899";>CVE-2015-0899</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2016-1181";>CVE-2016-1181</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2016-1182";>CVE-2016-1182</a>, Apache 
Struts 1 CVEs via velocity-tools transitive dependency</h3>
+                    <div class="panel callout">
+                        <p class="subheader">
+                            <strong>Status:</strong>
+                            <span class="cdx-not-affected">not_affected</span>
+                        </p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 6.6.2-8.x</p>
+                    </div>
+                </header>
+
+                <h4>Description</h4>
+                <p>Scanners flag <code>velocity-tools-2.0.jar</code> with 
Apache Struts 1 CVEs because its POM declares a
+transitive dependency on <code>struts-core</code>, <code>struts-taglib</code> 
and <code>struts-tiles</code> 1.3.8. Solr does not
+ship any Struts jar — the dependency is excluded and only appears as a 
transitive POM listing
+(see SOLR-2849) — so these Struts vulnerabilities are not present in, or 
exploitable through, Solr.</p>
+
+                <h4>References</h4>
+                <ul>
+                        <li>CVE: <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2015-0899";>CVE-2015-0899</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2016-1181";>CVE-2016-1181</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2016-1182";>CVE-2016-1182</a></li>
+                </ul>
+            </article>
             <article id="cve-2015-5237" class="post panel radius">
                 <header class="post-header">
                     <h3 class="title"><a 
href="https://nvd.nist.gov/vuln/detail/CVE-2015-5237";>CVE-2015-5237</a>, 
protobuf-java</h3>
@@ -1067,7 +1054,7 @@ Users are also recommended to upgrade to Solr 9.8.0, 
which mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 6.5.0-today</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 6.5.0-7.x</p>
                     </div>
                 </header>
 
@@ -1127,7 +1114,7 @@ Users are also recommended to upgrade to Solr 9.8.0, 
which mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 4.6.0-today</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 4.6.0-7.x</p>
                     </div>
                 </header>
 
@@ -1147,7 +1134,7 @@ Users are also recommended to upgrade to Solr 9.8.0, 
which mitigates this issue
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> ~2.9-today</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 2.9-9.10</p>
                     </div>
                 </header>
 

Reply via email to