This is an automated email from the ASF dual-hosted git repository.
github-actions[bot] pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/solr-site.git
The following commit(s) were added to refs/heads/asf-staging by this push:
new b471716f3 Commit build products
b471716f3 is described below
commit b471716f3ad33baa6a6321c80ed37e37a4fb3f4e
Author: Build Pelican (action) <[email protected]>
AuthorDate: Sun Jun 21 19:00:53 2026 +0000
Commit build products
---
output/feeds/all.atom.xml | 34 +--------
output/feeds/solr/vex.atom.xml | 2 +-
output/solr.vex.json | 169 +++++++++++++++++++++++------------------
output/vex.html | 20 +++++
4 files changed, 116 insertions(+), 109 deletions(-)
diff --git a/output/feeds/all.atom.xml b/output/feeds/all.atom.xml
index 85d68a7a1..4c2c2d944 100644
--- a/output/feeds/all.atom.xml
+++ b/output/feeds/all.atom.xml
@@ -480,7 +480,7 @@ Damon Toey (reporter)</p>
<p>Please refer to the Upgrade Notes in the Solr Ref Guide for
information on upgrading from previous Solr versions:</p>
<p><a
href="https://solr.apache.org/guide/solr/9_10/upgrade-notes/solr-upgrade-notes.html">https://solr.apache.org/guide/solr/9_10/upgrade-notes/solr-upgrade-notes.html</a></p>
<p>Please read CHANGELOG.md for a full list of new features, changes and
bugfixes:</p>
-<p><a
href="https://solr.apache.org/9_10_0/changes/Changes.html">https://solr.apache.org/9_10_0/changes/Changes.html</a></p></content><category
term="solr/news"/></entry><entry><title>protobuf-java: Potential Denial of
Service issue</title><link href="/cve-2024-7254.html"
rel="alternate"/><published>2025-08-02T00:00:00+00:00</published><updated>2025-08-02T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-08-02:/cve-2024-7254.ht [...]
+<p><a
href="https://solr.apache.org/9_10_0/changes/Changes.html">https://solr.apache.org/9_10_0/changes/Changes.html</a></p></content><category
term="solr/news"/></entry><entry><title>commons-lang3-.jar</title><link
href="/cve-2025-48924.html"
rel="alternate"/><published>2025-08-04T00:00:00+00:00</published><updated>2025-08-04T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-08-04:/cve-2025-48924.html</id><content
type="html"> [...]
Successful exploitation requires a very specific and non-standard
configuration.
The following conditions <strong>must all be
met</strong>:</p>
<ul>
@@ -1599,34 +1599,4 @@ See <a
href="https://lists.apache.org/thread/kgh63sncrsm2bls884pg87mnt8vqztmz
<p>Several enhancements and bug fixes for Solr's Parallel SQL interface,
included upgrading Apache Calcite to 1.27.0 (SOLR-15460, SOLR-15451,
SOLR-15456, SOLR-15461, SOLR-15489, SOLR-15475, SOLR-15499, SOLR-15570,
SOLR-15576, SOLR-9853, SOLR-15579, SOLR-15566)</p>
<p>A summary of important changes is published in the Solr Reference
Guide at <a
href="https://solr.apache.org/guide/8_10/solr-upgrade-notes.html">https://solr.apache.org/guide/8_10/solr-upgrade-notes.html</a>.</p>
<p>For the most exhaustive list, see the full release notes at <a
href="https://solr.apache.org/8_10_0/changes/Changes.html">https://solr.apache.org/8_10_0/changes/Changes.html</a>
or by viewing the CHANGES.txt file accompanying the distribution.</p>
-<p>Solr's release notes usually don't include Lucene layer changes.
Lucene's release notes are at <a
href="https://lucene.apache.org/core/8_10_0/changes/Changes.html">https://lucene.apache.org/core/8_10_0/changes/Changes.html</a></p></content><category
term="solr/news"/></entry><entry><title>Apache Solr Operatorâ„¢ v0.4.0
available</title><link href="/apache-solr-operatortm-v040-available.html"
rel="alternate"/><published>2021-09-13T00:00:00+00:00</published><updat [...]
-<p>The Apache Solr Operator is a safe and easy way of managing a Solr
ecosystem in Kubernetes.</p>
-<p>This release contains numerous bug fixes, optimizations, and
improvements, some of which are highlighted below …</p></summary><content
type="html"><p>The Apache Solr PMC is pleased to announce the release of
the Apache Solr Operator v0.4.0.</p>
-<p>The Apache Solr Operator is a safe and easy way of managing a Solr
ecosystem in Kubernetes.</p>
-<p>This release contains numerous bug fixes, optimizations, and
improvements, some of which are highlighted below. The release is available for
immediate download at:</p>
-<p><a
href="https://solr.apache.org/operator/artifacts.html">https://solr.apache.org/operator/artifacts.html</a></p>
-<h3 id="solr-operator-v040-release-highlights">Solr Operator v0.4.0
Release Highlights:<a class="headerlink"
href="#solr-operator-v040-release-highlights" title="Permanent
link">&para;</a></h3>
-<ul>
-<li>A new Helm chart for templating the Solr resource.</li>
-<li>Users must still run the Solr Operator, preferably through the Solr
Operator Helm chart.</li>
-<li>Support for hostpath for the Solr data volume when in ephemeral
mode</li>
-<li>Scheduled restarts of Solr Clouds and Solr Prometheus
Exporters</li>
-<li>The default version of Solr has been upgraded to 8.9</li>
-<li>Allow for custom service accounts to be used when running
Solr</li>
-<li>Upgrade the Zookeeper Operator dependency to v0.2.12</li>
-<li>Allow for ephemeral storage when running a provided Zookeeper
cluster</li>
-<li>The storage type for Zookeeper will default to the option chosen for
Solr</li>
-<li>Enable configuration of provided Zookeeper Config options</li>
-<li>Use a more secure base image for the Solr Operator</li>
-<li>The PrometheusExporter now accepts custom pod probes (liveness,
readiness, startup)</li>
-<li>Fix permissions in the default bootstrapped security.json</li>
-<li>Allow for terminating the Solr TLS at the ingress</li>
-<li>Allow for loading in TLS information from a mounted directory
(SolrCloud and SolrPrometheusExporter)</li>
-<li>SolrCloud now supports separate server and client certs for
mTLS</li>
-<li>The Solr Operator supports hot-reloading of TLS client certs used to
connect to Solr (enabled by default)</li>
-</ul>
-<p>A summary of important changes is published in the documentation
at:</p>
-<p><a
href="https://apache.github.io/solr-operator/docs/upgrade-notes.html">https://apache.github.io/solr-operator/docs/upgrade-notes.html</a></p>
-<p>For the most exhaustive list, see the change log on ArtifactHub or
view the git history in the solr-operator repo.</p>
-<p><a
href="https://artifacthub.io/packages/helm/apache-solr/solr-operator?modal=changelog">https://artifacthub.io/packages/helm/apache-solr/solr-operator?modal=changelog</a></p>
-<p><a
href="https://github.com/apache/solr-operator/releases/tag/v0.4.0">https://github.com/apache/solr-operator/releases/tag/v0.4.0</a></p></content><category
term="solr/operator/news"/></entry></feed>
\ No newline at end of file
+<p>Solr's release notes usually don't include Lucene layer changes.
Lucene's release notes are at <a
href="https://lucene.apache.org/core/8_10_0/changes/Changes.html">https://lucene.apache.org/core/8_10_0/changes/Changes.html</a></p></content><category
term="solr/news"/></entry></feed>
\ No newline at end of file
diff --git a/output/feeds/solr/vex.atom.xml b/output/feeds/solr/vex.atom.xml
index cd8910192..bd5618645 100644
--- a/output/feeds/solr/vex.atom.xml
+++ b/output/feeds/solr/vex.atom.xml
@@ -248,7 +248,7 @@ is referenced only inside Log4j's own JARs.
Neither Solr nor any of its bundled dependencies ever constructs or logs such
a message.</p>
<p>Because no shipped code can hand a triggering value to the layout,
the vulnerable code path cannot be reached regardless of the configured layout,
-and the Solr community considers this vulnerability
<strong>non-exploitable</strong> in the binary
distribution.</p></content><category
term="solr/vex"/></entry><entry><title>protobuf-java: Potential Denial of
Service issue</title><link href="/cve-2024-7254.html"
rel="alternate"/><published>2025-08-02T00:00:00+00:00</published><updated>2025-08-02T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-08-02:/cve-2024-7254.html</id><content
[...]
+and the Solr community considers this vulnerability
<strong>non-exploitable</strong> in the binary
distribution.</p></content><category
term="solr/vex"/></entry><entry><title>commons-lang3-.jar</title><link
href="/cve-2025-48924.html"
rel="alternate"/><published>2025-08-04T00:00:00+00:00</published><updated>2025-08-04T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-08-04:/cve-2025-48924.html</id><content
type="html"><p>The vu [...]
Successful exploitation requires a very specific and non-standard
configuration.
The following conditions <strong>must all be
met</strong>:</p>
<ul>
diff --git a/output/solr.vex.json b/output/solr.vex.json
index bd2c632e8..c01cda8ff 100644
--- a/output/solr.vex.json
+++ b/output/solr.vex.json
@@ -7,7 +7,7 @@
"name": "solr",
"version": "SNAPSHOT",
"type": "application",
- "bom-ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "bom-ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
},
"vulnerabilities": [
@@ -23,7 +23,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -39,7 +39,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -55,7 +55,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -71,7 +71,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -87,7 +87,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -103,7 +103,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -119,7 +119,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -135,7 +135,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -151,7 +151,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -167,7 +167,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -183,7 +183,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -199,7 +199,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -215,7 +215,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -231,7 +231,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -247,7 +247,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -263,7 +263,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -279,7 +279,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -295,7 +295,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -311,7 +311,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -327,7 +327,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -343,7 +343,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -359,7 +359,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -375,7 +375,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -391,7 +391,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -407,7 +407,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -423,7 +423,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -439,7 +439,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -455,7 +455,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -471,7 +471,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -487,7 +487,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -503,7 +503,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -519,7 +519,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -535,7 +535,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -551,7 +551,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -567,7 +567,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -583,7 +583,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -599,7 +599,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -615,7 +615,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -631,7 +631,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -647,7 +647,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -663,7 +663,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -679,7 +679,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -695,7 +695,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -711,7 +711,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -727,7 +727,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -743,7 +743,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -759,7 +759,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -775,7 +775,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -791,7 +791,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -807,7 +807,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -823,7 +823,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -839,7 +839,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -855,7 +855,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -871,7 +871,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -887,7 +887,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -903,7 +903,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -919,7 +919,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -935,7 +935,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -951,7 +951,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -970,7 +970,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -986,7 +986,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1002,7 +1002,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1018,7 +1018,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1037,7 +1037,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1053,7 +1053,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1070,7 +1070,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1086,7 +1086,24 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
+ }
+ ]
+ },
+ {
+ "id": "CVE-2025-48924",
+ "source": {
+ "name": "NVD",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48924"
+ },
+ "analysis": {
+ "state": "not_affected",
+ "justification": "code_not_reachable",
+ "detail": "The vulnerable functionality is only reachable via
`commons-configuration2`, which is used in Solr's Hadoop Kerberos support
(`solr-hadoop-auth`) to load administrator-provided Hadoop configuration files.
As such, the vulnerability is not exploitable in Solr."
+ },
+ "affects": [
+ {
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1103,7 +1120,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1120,7 +1137,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1137,7 +1154,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1154,7 +1171,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1171,7 +1188,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1191,7 +1208,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1211,7 +1228,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
},
@@ -1231,7 +1248,7 @@
},
"affects": [
{
- "ref": "0edd6956-499a-5872-92f9-1e68ba9c16b9"
+ "ref": "87b0825f-3532-5af7-be6b-bfda783d5759"
}
]
}
diff --git a/output/vex.html b/output/vex.html
index 0a37107b4..89a9591d3 100644
--- a/output/vex.html
+++ b/output/vex.html
@@ -539,6 +539,26 @@ with <code>log4j-core-2.25.4.jar</code>.</p>
<li>CVE: <a
href="https://nvd.nist.gov/vuln/detail/CVE-2026-34477">CVE-2026-34477</a></li>
</ul>
</article>
+ <article id="cve-2025-48924" class="post panel radius">
+ <header class="post-header">
+ <h3 class="title"><a
href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924">CVE-2025-48924</a>,
commons-lang3-<version>.jar</h3>
+ <div class="panel callout">
+ <p class="subheader">
+ <strong>Status:</strong>
+ <span class="cdx-not-affected">not_affected</span>
+ </p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 9.0.0-9.9.0</p>
+ </div>
+ </header>
+
+ <h4>Description</h4>
+ <p>The vulnerable functionality is only reachable via
<code>commons-configuration2</code>, which is used in Solr's Hadoop Kerberos
support (<code>solr-hadoop-auth</code>) to load administrator-provided Hadoop
configuration files. As such, the vulnerability is not exploitable in Solr.</p>
+
+ <h4>References</h4>
+ <ul>
+ <li>CVE: <a
href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924">CVE-2025-48924</a></li>
+ </ul>
+ </article>
<article id="cve-2024-7254" class="post panel radius">
<header class="post-header">
<h3 class="title"><a
href="https://nvd.nist.gov/vuln/detail/CVE-2024-7254">CVE-2024-7254</a>,
protobuf-java: Potential Denial of Service issue</h3>