This is an automated email from the ASF dual-hosted git repository.
github-actions[bot] pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/solr-site.git
The following commit(s) were added to refs/heads/asf-staging by this push:
new 64488a66d Commit build products
64488a66d is described below
commit 64488a66dd0d4ba8b18abecc45b4d4f80d95106f
Author: Build Pelican (action) <[email protected]>
AuthorDate: Thu Aug 13 01:34:46 2026 +0000
Commit build products
---
output/feeds/all.atom.xml | 32 +++-
output/feeds/solr/vex.atom.xml | 32 +++-
output/security-dependency-cves.html | 8 +-
output/solr.openvex.json | 33 ++--
output/solr.vex.json | 308 +++++++++++++++++------------------
output/vex.html | 40 +++--
6 files changed, 243 insertions(+), 210 deletions(-)
diff --git a/output/feeds/all.atom.xml b/output/feeds/all.atom.xml
index ca60fe072..77d32f7f2 100644
--- a/output/feeds/all.atom.xml
+++ b/output/feeds/all.atom.xml
@@ -17,10 +17,14 @@ avro &lt; 1.11.3). Both require the application to feed
attacker-controlled
own internal machinery, driven by administrator-supplied configuration, not
by untrusted request
input.</li>
</ul>
-<p>The affected range covers the 9.x line, where the optional Hadoop
modules transitively carry Avro
-1.9.2; Solr's own code path never invokes it. A scanner surfaces this as
<code>[email protected]</code> because Avro is
-shaded inside <code>hadoop-client-runtime-3.4.0.jar</code> in the
<code>hdfs</code> module (this is the form reported by
-SOLR-17900); it is the same non-reachable Hadoop transitive either
way.</p></content><category
term="solr/vex"/></entry><entry><title>jackson-core: memory disclosure via
source snippet in JsonLocation error messages</title><link
href="/cve-2025-49128.html"
rel="alternate"/><published>2026-07-31T00:00:00+00:00</published><updated>2026-07-31T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2026-07-31:/cve-2025-49128.html</id><summary
type="html"><p [...]
+<p>The affected range covers Solr 9.0.0 – 9.10.1, where the optional
Hadoop modules transitively carry a
+vulnerable Avro (1.7.7 in <code>hadoop-client-runtime</code> 3.3.2
– 3.3.6, then 1.9.2 in 3.4.0 – 3.4.1); Solr's
+own code path never invokes it. A scanner surfaces this as
<code>[email protected]</code> because Avro is shaded inside
+<code>hadoop-client-runtime</code> in the
<code>hdfs</code> module (the form reported by SOLR-17900). Unlike
the other
+Hadoop-shaded CVEs from SOLR-17900, Avro stayed vulnerable all the way through
9.10.1: Solr 9.11
+(branch_9x) is the first fixed release, having upgraded to Hadoop 3.4.3, whose
<code>hadoop-client-runtime</code>
+shades Avro 1.11.4 (past both the 1.11.3 and 1.11.4 fixes). Solr 10.x ships no
<code>hadoop-client-runtime</code>.
+Either way it is the same non-reachable Hadoop
transitive.</p></content><category
term="solr/vex"/></entry><entry><title>jackson-core: memory disclosure via
source snippet in JsonLocation error messages</title><link
href="/cve-2025-49128.html"
rel="alternate"/><published>2026-07-31T00:00:00+00:00</published><updated>2026-07-31T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2026-07-31:/cve-2025-49128.html</id><summary
type="html"><p>CVE-2025- [...]
includes in <code>JsonLocation</code> (e.g. surfaced in
parse-error messages). It affects jackson-core &lt; 2.13.0.</p>
<p>Solr is <strong>not affected</strong>. Solr's own
jackson-core is 2.18.0 in current 9.x and 2.22.0 in 9.11 — both
…</p></summary><content type="html"><p>CVE-2025-49128 can disclose
adjacent buffer memory through the source snippet that jackson-core
includes in <code>JsonLocation</code> (e.g. surfaced in
parse-error messages). It affects jackson-core &lt; 2.13.0.</p>
@@ -1542,8 +1546,10 @@ application parses attacker-supplied JOSE/JWT input with
Nimbus.</p>
scanner flags (<code>[email protected]</code>) is shaded inside
<code>hadoop-client-runtime</code> in the optional
<code>hdfs</code> module and is only used by Hadoop's own internal
auth machinery — Solr never routes an
untrusted, externally-supplied JOSE object to it. The vulnerable parser is
therefore not reached. The
-affected range spans the releases whose <code>hdfs</code> module
bundles the affected shaded Nimbus (Solr
-9.0.0 – 9.10.1); Solr 10.x ships no
<code>hadoop-client-runtime</code>.</p></content><category
term="solr/vex"/></entry><entry><title>Apache James MIME4J: header injection
when composing MIME messages</title><link href="/cve-2024-21742.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-21742.html</id><summary
type="html"><p> [...]
+affected range spans the releases whose <code>hdfs</code> module
bundles an affected shaded Nimbus — Solr
+9.0.0 – 9.9.0 (<code>hadoop-client-runtime</code> 3.3.2 – 3.4.0,
shading Nimbus ≤ 9.31). Solr 9.10.0 upgraded to
+Hadoop 3.4.1, whose <code>hadoop-client-runtime</code> shades the
fixed Nimbus 9.37.2, and Solr 10.x ships no
+<code>hadoop-client-runtime</code>, so neither is
affected.</p></content><category
term="solr/vex"/></entry><entry><title>Apache James MIME4J: header injection
when composing MIME messages</title><link href="/cve-2024-21742.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-21742.html</id><summary
type="html"><p>CVE-2024-21 [...]
used to <strong>compose / write</strong> MIME messages, improper
input validation lets crafted field values inject
unintended headers into the produced message. It affects
<code>apache-mime4j</code> before 0.8.10 (fixed in
0.8.10), and is …</p></summary><content
type="html"><p>CVE-2024-21742 (CVSS 5.3) is a header-injection issue in
Apache James MIME4J: when the library is
@@ -1572,7 +1578,9 @@ where Hadoop may use it for name resolution. Solr uses
the HDFS module only as a
connects to operator-configured HDFS NameNode/DataNode hosts, not
attacker-controlled names, and it
does not rely on dnsjava's DNSSEC validation to make any security decision.
The vulnerable resolver
path is therefore not reached. The affected range spans the releases whose
<code>hdfs</code> module bundles an
-affected shaded dnsjava (Solr 9.0.0 – 9.10.1); Solr 10.x ships no
<code>hadoop-client-runtime</code>.</p></content><category
term="solr/vex"/></entry><entry><title>Apache Commons Compress:
OutOfMemoryError unpacking a broken Pack200 file</title><link
href="/cve-2024-26308.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-26308.h [...]
+affected shaded dnsjava — Solr 9.0.0 – 9.9.0
(<code>hadoop-client-runtime</code> 3.3.2 – 3.4.0, shading dnsjava
+≤ 3.4.0). Solr 9.10.0 upgraded to Hadoop 3.4.1, whose
<code>hadoop-client-runtime</code> shades the fixed dnsjava
+3.6.1, and Solr 10.x ships no <code>hadoop-client-runtime</code>,
so neither is affected.</p></content><category
term="solr/vex"/></entry><entry><title>Apache Commons Compress:
OutOfMemoryError unpacking a broken Pack200 file</title><link
href="/cve-2024-26308.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-26308.html</id><sum
[...]
malformed <strong>Pack200</strong>
(<code>.pack</code>/<code>.pack.gz</code>) stream can
allocate excessive memory and throw
<code>OutOfMemoryError</code> (affects 1.21 through 1.25.0, fixed
in 1.26.0). It is reachable only when an
application uses Commons Compress to …</p></summary><content
type="html"><p>CVE-2024-26308 (CVSS 6.7) is a denial-of-service issue in
Apache Commons Compress: unpacking a
@@ -1585,7 +1593,10 @@ format) is not part of any Solr request path. The
affected <code>commons-c
module; Solr's HDFS-client usage does not feed untrusted Pack200 input to it,
and Solr's own use of
Commons Compress elsewhere does not invoke the Pack200 unpacker. The
vulnerable code path is therefore
not reached. The affected range spans the releases whose
<code>hdfs</code> module bundles an affected shaded
-commons-compress (Solr 9.0.0 – 9.10.1); Solr 10.x ships no
<code>hadoop-client-runtime</code>.</p></content><category
term="solr/vex"/></entry><entry><title>Apache Commons Configuration:
StackOverflowError in list-delimiter handling</title><link
href="/cve-2024-29131.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-29131.html</ [...]
+commons-compress — Solr 9.0.0 – 9.9.0
(<code>hadoop-client-runtime</code> 3.3.2 – 3.4.0, shading
commons-compress
+≤ 1.24.0; the standalone copy in the <code>extraction</code>
module was already ≥ 1.26.0 by 9.7.0). Solr 9.10.0
+upgraded to Hadoop 3.4.1, whose <code>hadoop-client-runtime</code>
shades the fixed commons-compress 1.26.1, and
+Solr 10.x ships no <code>hadoop-client-runtime</code>, so neither
is affected.</p></content><category
term="solr/vex"/></entry><entry><title>Apache Commons Configuration:
StackOverflowError in list-delimiter handling</title><link
href="/cve-2024-29131.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-29131.html</id><summary
type [...]
Configuration's list-delimiter handling —
<code>AbstractListDelimiterHandler.flattenIterator(...)</code> and
<code>ListDelimiterHandler.flatten(Object, int)</code>
respectively — when a configuration contains a cyclic
reference (both affect 2.0 through 2.10.0, fixed in 2.10.1).</p>
@@ -1600,7 +1611,10 @@ integration — both the standalone copy in the
<code>hadoop-auth</code
path feeds attacker-controlled configuration to Commons Configuration, so the
recursive list-delimiter
parser cannot be driven by an adversary. This matches the existing assessment
of the other Commons
Configuration CVEs (CVE-2022-33980, CVE-2026-45205). The affected range spans
the releases whose
-Hadoop modules carry an affected commons-configuration2 (Solr 9.0.0 –
9.10.1).</p></content><category
term="solr/vex"/></entry><entry><title>Apache POI: improper input validation
parsing OOXML files</title><link href="/cve-2025-31672.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2025-31672.html</id><summary
type="html"><p>CVE-2025-3167 [...]
+Hadoop modules carry an affected commons-configuration2 — Solr 9.0.0 – 9.9.0
(<code>hadoop-client-runtime</code>
+3.3.2 – 3.4.0 shades commons-configuration2 ≤ 2.8.0; the standalone
<code>hadoop-auth</code> copy was already
+≥ 2.10.1, at 2.11.0, by 9.7.0). Solr 9.10.0 upgraded to Hadoop 3.4.1, whose
<code>hadoop-client-runtime</code>
+shades the fixed commons-configuration2 2.10.1, so 9.10.x onward is not
affected.</p></content><category
term="solr/vex"/></entry><entry><title>Apache POI: improper input validation
parsing OOXML files</title><link href="/cve-2025-31672.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2025-31672.html</id><summary
type="html"><p>CVE-2025-3 [...]
a crafted OOXML file (<code>.xlsx</code>,
<code>.docx</code>, etc.) can cause
<code>poi-ooxml</code> to read unexpected data or consume
excessive resources. It affects all <code>poi-ooxml</code>
releases before 5.4.0 (fixed in 5.4.0). Solr bundles
an affected …</p></summary><content type="html"><p>CVE-2025-31672
(CVSS 6.9) is an improper-input-validation issue in Apache POI's OOXML parser:
parsing
diff --git a/output/feeds/solr/vex.atom.xml b/output/feeds/solr/vex.atom.xml
index 6ba853bd0..050295bf0 100644
--- a/output/feeds/solr/vex.atom.xml
+++ b/output/feeds/solr/vex.atom.xml
@@ -17,10 +17,14 @@ avro &lt; 1.11.3). Both require the application to feed
attacker-controlled
own internal machinery, driven by administrator-supplied configuration, not
by untrusted request
input.</li>
</ul>
-<p>The affected range covers the 9.x line, where the optional Hadoop
modules transitively carry Avro
-1.9.2; Solr's own code path never invokes it. A scanner surfaces this as
<code>[email protected]</code> because Avro is
-shaded inside <code>hadoop-client-runtime-3.4.0.jar</code> in the
<code>hdfs</code> module (this is the form reported by
-SOLR-17900); it is the same non-reachable Hadoop transitive either
way.</p></content><category
term="solr/vex"/></entry><entry><title>jackson-core: memory disclosure via
source snippet in JsonLocation error messages</title><link
href="/cve-2025-49128.html"
rel="alternate"/><published>2026-07-31T00:00:00+00:00</published><updated>2026-07-31T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2026-07-31:/cve-2025-49128.html</id><summary
type="html"><p [...]
+<p>The affected range covers Solr 9.0.0 – 9.10.1, where the optional
Hadoop modules transitively carry a
+vulnerable Avro (1.7.7 in <code>hadoop-client-runtime</code> 3.3.2
– 3.3.6, then 1.9.2 in 3.4.0 – 3.4.1); Solr's
+own code path never invokes it. A scanner surfaces this as
<code>[email protected]</code> because Avro is shaded inside
+<code>hadoop-client-runtime</code> in the
<code>hdfs</code> module (the form reported by SOLR-17900). Unlike
the other
+Hadoop-shaded CVEs from SOLR-17900, Avro stayed vulnerable all the way through
9.10.1: Solr 9.11
+(branch_9x) is the first fixed release, having upgraded to Hadoop 3.4.3, whose
<code>hadoop-client-runtime</code>
+shades Avro 1.11.4 (past both the 1.11.3 and 1.11.4 fixes). Solr 10.x ships no
<code>hadoop-client-runtime</code>.
+Either way it is the same non-reachable Hadoop
transitive.</p></content><category
term="solr/vex"/></entry><entry><title>jackson-core: memory disclosure via
source snippet in JsonLocation error messages</title><link
href="/cve-2025-49128.html"
rel="alternate"/><published>2026-07-31T00:00:00+00:00</published><updated>2026-07-31T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2026-07-31:/cve-2025-49128.html</id><summary
type="html"><p>CVE-2025- [...]
includes in <code>JsonLocation</code> (e.g. surfaced in
parse-error messages). It affects jackson-core &lt; 2.13.0.</p>
<p>Solr is <strong>not affected</strong>. Solr's own
jackson-core is 2.18.0 in current 9.x and 2.22.0 in 9.11 — both
…</p></summary><content type="html"><p>CVE-2025-49128 can disclose
adjacent buffer memory through the source snippet that jackson-core
includes in <code>JsonLocation</code> (e.g. surfaced in
parse-error messages). It affects jackson-core &lt; 2.13.0.</p>
@@ -1310,8 +1314,10 @@ application parses attacker-supplied JOSE/JWT input with
Nimbus.</p>
scanner flags (<code>[email protected]</code>) is shaded inside
<code>hadoop-client-runtime</code> in the optional
<code>hdfs</code> module and is only used by Hadoop's own internal
auth machinery — Solr never routes an
untrusted, externally-supplied JOSE object to it. The vulnerable parser is
therefore not reached. The
-affected range spans the releases whose <code>hdfs</code> module
bundles the affected shaded Nimbus (Solr
-9.0.0 – 9.10.1); Solr 10.x ships no
<code>hadoop-client-runtime</code>.</p></content><category
term="solr/vex"/></entry><entry><title>Apache James MIME4J: header injection
when composing MIME messages</title><link href="/cve-2024-21742.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-21742.html</id><summary
type="html"><p> [...]
+affected range spans the releases whose <code>hdfs</code> module
bundles an affected shaded Nimbus — Solr
+9.0.0 – 9.9.0 (<code>hadoop-client-runtime</code> 3.3.2 – 3.4.0,
shading Nimbus ≤ 9.31). Solr 9.10.0 upgraded to
+Hadoop 3.4.1, whose <code>hadoop-client-runtime</code> shades the
fixed Nimbus 9.37.2, and Solr 10.x ships no
+<code>hadoop-client-runtime</code>, so neither is
affected.</p></content><category
term="solr/vex"/></entry><entry><title>Apache James MIME4J: header injection
when composing MIME messages</title><link href="/cve-2024-21742.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-21742.html</id><summary
type="html"><p>CVE-2024-21 [...]
used to <strong>compose / write</strong> MIME messages, improper
input validation lets crafted field values inject
unintended headers into the produced message. It affects
<code>apache-mime4j</code> before 0.8.10 (fixed in
0.8.10), and is …</p></summary><content
type="html"><p>CVE-2024-21742 (CVSS 5.3) is a header-injection issue in
Apache James MIME4J: when the library is
@@ -1340,7 +1346,9 @@ where Hadoop may use it for name resolution. Solr uses
the HDFS module only as a
connects to operator-configured HDFS NameNode/DataNode hosts, not
attacker-controlled names, and it
does not rely on dnsjava's DNSSEC validation to make any security decision.
The vulnerable resolver
path is therefore not reached. The affected range spans the releases whose
<code>hdfs</code> module bundles an
-affected shaded dnsjava (Solr 9.0.0 – 9.10.1); Solr 10.x ships no
<code>hadoop-client-runtime</code>.</p></content><category
term="solr/vex"/></entry><entry><title>Apache Commons Compress:
OutOfMemoryError unpacking a broken Pack200 file</title><link
href="/cve-2024-26308.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-26308.h [...]
+affected shaded dnsjava — Solr 9.0.0 – 9.9.0
(<code>hadoop-client-runtime</code> 3.3.2 – 3.4.0, shading dnsjava
+≤ 3.4.0). Solr 9.10.0 upgraded to Hadoop 3.4.1, whose
<code>hadoop-client-runtime</code> shades the fixed dnsjava
+3.6.1, and Solr 10.x ships no <code>hadoop-client-runtime</code>,
so neither is affected.</p></content><category
term="solr/vex"/></entry><entry><title>Apache Commons Compress:
OutOfMemoryError unpacking a broken Pack200 file</title><link
href="/cve-2024-26308.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-26308.html</id><sum
[...]
malformed <strong>Pack200</strong>
(<code>.pack</code>/<code>.pack.gz</code>) stream can
allocate excessive memory and throw
<code>OutOfMemoryError</code> (affects 1.21 through 1.25.0, fixed
in 1.26.0). It is reachable only when an
application uses Commons Compress to …</p></summary><content
type="html"><p>CVE-2024-26308 (CVSS 6.7) is a denial-of-service issue in
Apache Commons Compress: unpacking a
@@ -1353,7 +1361,10 @@ format) is not part of any Solr request path. The
affected <code>commons-c
module; Solr's HDFS-client usage does not feed untrusted Pack200 input to it,
and Solr's own use of
Commons Compress elsewhere does not invoke the Pack200 unpacker. The
vulnerable code path is therefore
not reached. The affected range spans the releases whose
<code>hdfs</code> module bundles an affected shaded
-commons-compress (Solr 9.0.0 – 9.10.1); Solr 10.x ships no
<code>hadoop-client-runtime</code>.</p></content><category
term="solr/vex"/></entry><entry><title>Apache Commons Configuration:
StackOverflowError in list-delimiter handling</title><link
href="/cve-2024-29131.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-29131.html</ [...]
+commons-compress — Solr 9.0.0 – 9.9.0
(<code>hadoop-client-runtime</code> 3.3.2 – 3.4.0, shading
commons-compress
+≤ 1.24.0; the standalone copy in the <code>extraction</code>
module was already ≥ 1.26.0 by 9.7.0). Solr 9.10.0
+upgraded to Hadoop 3.4.1, whose <code>hadoop-client-runtime</code>
shades the fixed commons-compress 1.26.1, and
+Solr 10.x ships no <code>hadoop-client-runtime</code>, so neither
is affected.</p></content><category
term="solr/vex"/></entry><entry><title>Apache Commons Configuration:
StackOverflowError in list-delimiter handling</title><link
href="/cve-2024-29131.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-29131.html</id><summary
type [...]
Configuration's list-delimiter handling —
<code>AbstractListDelimiterHandler.flattenIterator(...)</code> and
<code>ListDelimiterHandler.flatten(Object, int)</code>
respectively — when a configuration contains a cyclic
reference (both affect 2.0 through 2.10.0, fixed in 2.10.1).</p>
@@ -1368,7 +1379,10 @@ integration — both the standalone copy in the
<code>hadoop-auth</code
path feeds attacker-controlled configuration to Commons Configuration, so the
recursive list-delimiter
parser cannot be driven by an adversary. This matches the existing assessment
of the other Commons
Configuration CVEs (CVE-2022-33980, CVE-2026-45205). The affected range spans
the releases whose
-Hadoop modules carry an affected commons-configuration2 (Solr 9.0.0 –
9.10.1).</p></content><category
term="solr/vex"/></entry><entry><title>Apache POI: improper input validation
parsing OOXML files</title><link href="/cve-2025-31672.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2025-31672.html</id><summary
type="html"><p>CVE-2025-3167 [...]
+Hadoop modules carry an affected commons-configuration2 — Solr 9.0.0 – 9.9.0
(<code>hadoop-client-runtime</code>
+3.3.2 – 3.4.0 shades commons-configuration2 ≤ 2.8.0; the standalone
<code>hadoop-auth</code> copy was already
+≥ 2.10.1, at 2.11.0, by 9.7.0). Solr 9.10.0 upgraded to Hadoop 3.4.1, whose
<code>hadoop-client-runtime</code>
+shades the fixed commons-configuration2 2.10.1, so 9.10.x onward is not
affected.</p></content><category
term="solr/vex"/></entry><entry><title>Apache POI: improper input validation
parsing OOXML files</title><link href="/cve-2025-31672.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2025-31672.html</id><summary
type="html"><p>CVE-2025-3 [...]
a crafted OOXML file (<code>.xlsx</code>,
<code>.docx</code>, etc.) can cause
<code>poi-ooxml</code> to read unexpected data or consume
excessive resources. It affects all <code>poi-ooxml</code>
releases before 5.4.0 (fixed in 5.4.0). Solr bundles
an affected …</p></summary><content type="html"><p>CVE-2025-31672
(CVSS 6.9) is an improper-input-validation issue in Apache POI's OOXML parser:
parsing
diff --git a/output/security-dependency-cves.html
b/output/security-dependency-cves.html
index 655040865..7d8b3831c 100644
--- a/output/security-dependency-cves.html
+++ b/output/security-dependency-cves.html
@@ -633,7 +633,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29131">CVE-2024-29131</a>,
<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29133">CVE-2024-29133</a>
</td>
- <td>9.0.0-9.10.1</td>
+ <td>9.0.0-9.9.0</td>
<td>
commons-configuration2-2.8.0.jar </td>
<td><span class="cdx-not-affected">not affected</span></td>
@@ -642,7 +642,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26308">CVE-2024-26308</a>
</td>
- <td>9.0.0-9.10.1</td>
+ <td>9.0.0-9.9.0</td>
<td>
commons-compress-1.24.0.jar </td>
<td><span class="cdx-not-affected">not affected</span></td>
@@ -651,7 +651,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25638">CVE-2024-25638</a>
</td>
- <td>9.0.0-9.10.1</td>
+ <td>9.0.0-9.9.0</td>
<td>
dnsjava-3.4.0.jar </td>
<td><span class="cdx-not-affected">not affected</span></td>
@@ -669,7 +669,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<tr>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52428">CVE-2023-52428</a>
</td>
- <td>9.0.0-9.10.1</td>
+ <td>9.0.0-9.9.0</td>
<td>
nimbus-jose-jwt-9.31.jar </td>
<td><span class="cdx-not-affected">not affected</span></td>
diff --git a/output/solr.openvex.json b/output/solr.openvex.json
index 7824993cb..74e33ae8d 100644
--- a/output/solr.openvex.json
+++ b/output/solr.openvex.json
@@ -1616,8 +1616,8 @@
"status": "not_affected",
"timestamp": "2025-09-07T00:00:00Z",
"justification": "vulnerable_code_not_in_execute_path",
- "impact_statement": "CVE-2023-52428 (CVSS 8.7) is a denial-of-service
issue in Nimbus JOSE + JWT: parsing a crafted JOSE\nobject (for example a
PBES2-encrypted JWE with a huge `p2c` iteration count, or a large
deeply-nested\nstructure) can consume excessive resources (fixed in 9.37.2). It
is only reachable when an\napplication parses attacker-supplied JOSE/JWT input
with Nimbus.\n\nSolr is **not affected**. Solr's own JWT authentication (the
optional `jwt-auth` module,\n`JWTAuthPlu [...]
- "status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
+ "impact_statement": "CVE-2023-52428 (CVSS 8.7) is a denial-of-service
issue in Nimbus JOSE + JWT: parsing a crafted JOSE\nobject (for example a
PBES2-encrypted JWE with a huge `p2c` iteration count, or a large
deeply-nested\nstructure) can consume excessive resources (fixed in 9.37.2). It
is only reachable when an\napplication parses attacker-supplied JOSE/JWT input
with Nimbus.\n\nSolr is **not affected**. Solr's own JWT authentication (the
optional `jwt-auth` module,\n`JWTAuthPlu [...]
+ "status_notes": "Affected Apache Solr versions: 9.0.0-9.9.0."
},
{
"vulnerability": {
@@ -1661,8 +1661,8 @@
"status": "not_affected",
"timestamp": "2025-09-07T00:00:00Z",
"justification": "vulnerable_code_not_in_execute_path",
- "impact_statement": "CVE-2024-25638 (CVSS 7.0) is a DNSSEC-validation
bypass in dnsjava: a resolver relying on dnsjava to\nvalidate DNSSEC could be
tricked into accepting spoofed records (affects dnsjava < 3.6.0). It
matters\nonly for an application that uses dnsjava as its resolver and relies
on its DNSSEC validation for a\nsecurity decision.\n\nSolr is **not affected**.
dnsjava is not a Solr dependency in its own right \u2014 it is shaded
inside\n`hadoop-client-runtime` (reported [...]
- "status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
+ "impact_statement": "CVE-2024-25638 (CVSS 7.0) is a DNSSEC-validation
bypass in dnsjava: a resolver relying on dnsjava to\nvalidate DNSSEC could be
tricked into accepting spoofed records (affects dnsjava < 3.6.0). It
matters\nonly for an application that uses dnsjava as its resolver and relies
on its DNSSEC validation for a\nsecurity decision.\n\nSolr is **not affected**.
dnsjava is not a Solr dependency in its own right \u2014 it is shaded
inside\n`hadoop-client-runtime` (reported [...]
+ "status_notes": "Affected Apache Solr versions: 9.0.0-9.9.0."
},
{
"vulnerability": {
@@ -1686,16 +1686,13 @@
},
{
"@id": "pkg:maven/org.apache.commons/[email protected]"
- },
- {
- "@id": "pkg:maven/org.apache.commons/[email protected]"
}
],
"status": "not_affected",
"timestamp": "2025-09-07T00:00:00Z",
"justification": "vulnerable_code_not_in_execute_path",
- "impact_statement": "CVE-2024-26308 (CVSS 6.7) is a denial-of-service
issue in Apache Commons Compress: unpacking a\nmalformed **Pack200**
(`.pack`/`.pack.gz`) stream can allocate excessive memory and
throw\n`OutOfMemoryError` (affects 1.21 through 1.25.0, fixed in 1.26.0). It is
reachable only when an\napplication uses Commons Compress to unpack an
attacker-supplied Pack200 archive.\n\nSolr is **not affected**. Solr never
unpacks Pack200 archives \u2014 Pack200 (a legacy JAR-compr [...]
- "status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
+ "impact_statement": "CVE-2024-26308 (CVSS 6.7) is a denial-of-service
issue in Apache Commons Compress: unpacking a\nmalformed **Pack200**
(`.pack`/`.pack.gz`) stream can allocate excessive memory and
throw\n`OutOfMemoryError` (affects 1.21 through 1.25.0, fixed in 1.26.0). It is
reachable only when an\napplication uses Commons Compress to unpack an
attacker-supplied Pack200 archive.\n\nSolr is **not affected**. Solr never
unpacks Pack200 archives \u2014 Pack200 (a legacy JAR-compr [...]
+ "status_notes": "Affected Apache Solr versions: 9.0.0-9.9.0."
},
{
"vulnerability": {
@@ -1708,9 +1705,6 @@
{
"@id": "pkg:maven/org.apache.commons/[email protected]"
},
- {
- "@id": "pkg:maven/org.apache.commons/[email protected]"
- },
{
"@id": "pkg:maven/org.apache.commons/[email protected]"
},
@@ -1724,8 +1718,8 @@
"status": "not_affected",
"timestamp": "2025-09-07T00:00:00Z",
"justification": "vulnerable_code_not_in_execute_path",
- "impact_statement": "CVE-2024-29131 and CVE-2024-29133 are
denial-of-service issues (StackOverflowError) in Apache
Commons\nConfiguration's list-delimiter handling \u2014
`AbstractListDelimiterHandler.flattenIterator(...)`
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0,
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses
`commons-configuration2` only through its optional Had [...]
- "status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
+ "impact_statement": "CVE-2024-29131 and CVE-2024-29133 are
denial-of-service issues (StackOverflowError) in Apache
Commons\nConfiguration's list-delimiter handling \u2014
`AbstractListDelimiterHandler.flattenIterator(...)`
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0,
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses
`commons-configuration2` only through its optional Had [...]
+ "status_notes": "Affected Apache Solr versions: 9.0.0-9.9.0."
},
{
"vulnerability": {
@@ -1738,9 +1732,6 @@
{
"@id": "pkg:maven/org.apache.commons/[email protected]"
},
- {
- "@id": "pkg:maven/org.apache.commons/[email protected]"
- },
{
"@id": "pkg:maven/org.apache.commons/[email protected]"
},
@@ -1754,8 +1745,8 @@
"status": "not_affected",
"timestamp": "2025-09-07T00:00:00Z",
"justification": "vulnerable_code_not_in_execute_path",
- "impact_statement": "CVE-2024-29131 and CVE-2024-29133 are
denial-of-service issues (StackOverflowError) in Apache
Commons\nConfiguration's list-delimiter handling \u2014
`AbstractListDelimiterHandler.flattenIterator(...)`
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0,
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses
`commons-configuration2` only through its optional Had [...]
- "status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
+ "impact_statement": "CVE-2024-29131 and CVE-2024-29133 are
denial-of-service issues (StackOverflowError) in Apache
Commons\nConfiguration's list-delimiter handling \u2014
`AbstractListDelimiterHandler.flattenIterator(...)`
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0,
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses
`commons-configuration2` only through its optional Had [...]
+ "status_notes": "Affected Apache Solr versions: 9.0.0-9.9.0."
},
{
"vulnerability": {
@@ -2971,7 +2962,7 @@
"status": "not_affected",
"timestamp": "2026-07-31T00:00:00Z",
"justification": "vulnerable_code_not_in_execute_path",
- "impact_statement": "CVE-2024-47561 (critical) is an
arbitrary-code-execution issue in the Apache Avro Java SDK: parsing\nan
attacker-controlled Avro **schema** can instantiate arbitrary classes (affects
avro < 1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is
**not affected**:\n\n* **Solr does not use Apache Avro. [...]
+ "impact_statement": "CVE-2024-47561 (critical) is an
arbitrary-code-execution issue in the Apache Avro Java SDK: parsing\nan
attacker-controlled Avro **schema** can instantiate arbitrary classes (affects
avro < 1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is
**not affected**:\n\n* **Solr does not use Apache Avro. [...]
"status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
},
{
@@ -2986,7 +2977,7 @@
"status": "not_affected",
"timestamp": "2026-07-31T00:00:00Z",
"justification": "vulnerable_code_not_in_execute_path",
- "impact_statement": "CVE-2024-47561 (critical) is an
arbitrary-code-execution issue in the Apache Avro Java SDK: parsing\nan
attacker-controlled Avro **schema** can instantiate arbitrary classes (affects
avro < 1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is
**not affected**:\n\n* **Solr does not use Apache Avro. [...]
+ "impact_statement": "CVE-2024-47561 (critical) is an
arbitrary-code-execution issue in the Apache Avro Java SDK: parsing\nan
attacker-controlled Avro **schema** can instantiate arbitrary classes (affects
avro < 1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is
**not affected**:\n\n* **Solr does not use Apache Avro. [...]
"status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
},
{
diff --git a/output/solr.vex.json b/output/solr.vex.json
index 3b376bfce..80c3d96fe 100644
--- a/output/solr.vex.json
+++ b/output/solr.vex.json
@@ -7,7 +7,7 @@
"name": "solr",
"version": "SNAPSHOT",
"type": "application",
- "bom-ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "bom-ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
},
"vulnerabilities": [
@@ -23,7 +23,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -39,7 +39,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -55,7 +55,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -71,7 +71,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -87,7 +87,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -103,7 +103,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -119,7 +119,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -135,7 +135,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -151,7 +151,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -167,7 +167,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -183,7 +183,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -199,7 +199,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -215,7 +215,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -231,7 +231,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -247,7 +247,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -263,7 +263,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -279,7 +279,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -295,7 +295,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -311,7 +311,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -327,7 +327,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -343,7 +343,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -359,7 +359,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -375,7 +375,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -391,7 +391,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -407,7 +407,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -423,7 +423,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -439,7 +439,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -455,7 +455,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -471,7 +471,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -487,7 +487,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -503,7 +503,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -519,7 +519,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -535,7 +535,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -551,7 +551,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -567,7 +567,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -583,7 +583,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -599,7 +599,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -615,7 +615,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -631,7 +631,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -647,7 +647,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -663,7 +663,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -679,7 +679,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -695,7 +695,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -711,7 +711,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -727,7 +727,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -743,7 +743,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -759,7 +759,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -775,7 +775,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -791,7 +791,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -807,7 +807,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -823,7 +823,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -839,7 +839,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -855,7 +855,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -871,7 +871,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -887,7 +887,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -903,7 +903,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -919,7 +919,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -935,7 +935,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -951,7 +951,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -970,7 +970,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -986,7 +986,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1002,7 +1002,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1018,7 +1018,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1037,7 +1037,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1053,7 +1053,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1070,7 +1070,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1087,7 +1087,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1104,7 +1104,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1121,7 +1121,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1138,7 +1138,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1155,7 +1155,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1172,7 +1172,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1185,11 +1185,11 @@
"analysis": {
"state": "not_affected",
"justification": "code_not_reachable",
- "detail": "CVE-2023-52428 (CVSS 8.7) is a denial-of-service issue in
Nimbus JOSE + JWT: parsing a crafted JOSE\nobject (for example a
PBES2-encrypted JWE with a huge `p2c` iteration count, or a large
deeply-nested\nstructure) can consume excessive resources (fixed in 9.37.2). It
is only reachable when an\napplication parses attacker-supplied JOSE/JWT input
with Nimbus.\n\nSolr is **not affected**. Solr's own JWT authentication (the
optional `jwt-auth` module,\n`JWTAuthPlugin`) pa [...]
+ "detail": "CVE-2023-52428 (CVSS 8.7) is a denial-of-service issue in
Nimbus JOSE + JWT: parsing a crafted JOSE\nobject (for example a
PBES2-encrypted JWE with a huge `p2c` iteration count, or a large
deeply-nested\nstructure) can consume excessive resources (fixed in 9.37.2). It
is only reachable when an\napplication parses attacker-supplied JOSE/JWT input
with Nimbus.\n\nSolr is **not affected**. Solr's own JWT authentication (the
optional `jwt-auth` module,\n`JWTAuthPlugin`) pa [...]
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1206,7 +1206,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1219,11 +1219,11 @@
"analysis": {
"state": "not_affected",
"justification": "code_not_reachable",
- "detail": "CVE-2024-25638 (CVSS 7.0) is a DNSSEC-validation bypass in
dnsjava: a resolver relying on dnsjava to\nvalidate DNSSEC could be tricked
into accepting spoofed records (affects dnsjava < 3.6.0). It matters\nonly for
an application that uses dnsjava as its resolver and relies on its DNSSEC
validation for a\nsecurity decision.\n\nSolr is **not affected**. dnsjava is
not a Solr dependency in its own right \u2014 it is shaded
inside\n`hadoop-client-runtime` (reported by scan [...]
+ "detail": "CVE-2024-25638 (CVSS 7.0) is a DNSSEC-validation bypass in
dnsjava: a resolver relying on dnsjava to\nvalidate DNSSEC could be tricked
into accepting spoofed records (affects dnsjava < 3.6.0). It matters\nonly for
an application that uses dnsjava as its resolver and relies on its DNSSEC
validation for a\nsecurity decision.\n\nSolr is **not affected**. dnsjava is
not a Solr dependency in its own right \u2014 it is shaded
inside\n`hadoop-client-runtime` (reported by scan [...]
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1236,11 +1236,11 @@
"analysis": {
"state": "not_affected",
"justification": "code_not_reachable",
- "detail": "CVE-2024-26308 (CVSS 6.7) is a denial-of-service issue in
Apache Commons Compress: unpacking a\nmalformed **Pack200**
(`.pack`/`.pack.gz`) stream can allocate excessive memory and
throw\n`OutOfMemoryError` (affects 1.21 through 1.25.0, fixed in 1.26.0). It is
reachable only when an\napplication uses Commons Compress to unpack an
attacker-supplied Pack200 archive.\n\nSolr is **not affected**. Solr never
unpacks Pack200 archives \u2014 Pack200 (a legacy JAR-compression\n [...]
+ "detail": "CVE-2024-26308 (CVSS 6.7) is a denial-of-service issue in
Apache Commons Compress: unpacking a\nmalformed **Pack200**
(`.pack`/`.pack.gz`) stream can allocate excessive memory and
throw\n`OutOfMemoryError` (affects 1.21 through 1.25.0, fixed in 1.26.0). It is
reachable only when an\napplication uses Commons Compress to unpack an
attacker-supplied Pack200 archive.\n\nSolr is **not affected**. Solr never
unpacks Pack200 archives \u2014 Pack200 (a legacy JAR-compression\n [...]
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1253,11 +1253,11 @@
"analysis": {
"state": "not_affected",
"justification": "code_not_reachable",
- "detail": "CVE-2024-29131 and CVE-2024-29133 are denial-of-service
issues (StackOverflowError) in Apache Commons\nConfiguration's list-delimiter
handling \u2014 `AbstractListDelimiterHandler.flattenIterator(...)`
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0,
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses
`commons-configuration2` only through its optional Hadoop\nint [...]
+ "detail": "CVE-2024-29131 and CVE-2024-29133 are denial-of-service
issues (StackOverflowError) in Apache Commons\nConfiguration's list-delimiter
handling \u2014 `AbstractListDelimiterHandler.flattenIterator(...)`
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0,
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses
`commons-configuration2` only through its optional Hadoop\nint [...]
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1270,11 +1270,11 @@
"analysis": {
"state": "not_affected",
"justification": "code_not_reachable",
- "detail": "CVE-2024-29131 and CVE-2024-29133 are denial-of-service
issues (StackOverflowError) in Apache Commons\nConfiguration's list-delimiter
handling \u2014 `AbstractListDelimiterHandler.flattenIterator(...)`
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0,
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses
`commons-configuration2` only through its optional Hadoop\nint [...]
+ "detail": "CVE-2024-29131 and CVE-2024-29133 are denial-of-service
issues (StackOverflowError) in Apache Commons\nConfiguration's list-delimiter
handling \u2014 `AbstractListDelimiterHandler.flattenIterator(...)`
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0,
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses
`commons-configuration2` only through its optional Hadoop\nint [...]
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1291,7 +1291,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1308,7 +1308,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1325,7 +1325,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1342,7 +1342,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1359,7 +1359,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1376,7 +1376,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1396,7 +1396,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1416,7 +1416,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1436,7 +1436,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1453,7 +1453,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1473,7 +1473,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1490,7 +1490,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1507,7 +1507,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1524,7 +1524,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1541,7 +1541,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1558,7 +1558,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1575,7 +1575,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1592,7 +1592,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1609,7 +1609,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1626,7 +1626,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1643,7 +1643,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1660,7 +1660,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1677,7 +1677,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1694,7 +1694,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1711,7 +1711,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1728,7 +1728,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1745,7 +1745,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1762,7 +1762,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1779,7 +1779,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1796,7 +1796,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1813,7 +1813,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1830,7 +1830,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1847,7 +1847,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1864,7 +1864,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1877,11 +1877,11 @@
"analysis": {
"state": "not_affected",
"justification": "code_not_reachable",
- "detail": "CVE-2024-47561 (critical) is an arbitrary-code-execution
issue in the Apache Avro Java SDK: parsing\nan attacker-controlled Avro
**schema** can instantiate arbitrary classes (affects avro <
1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is
**not affected**:\n\n* **Solr does not use Apache Avro.** There [...]
+ "detail": "CVE-2024-47561 (critical) is an arbitrary-code-execution
issue in the Apache Avro Java SDK: parsing\nan attacker-controlled Avro
**schema** can instantiate arbitrary classes (affects avro <
1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is
**not affected**:\n\n* **Solr does not use Apache Avro.** There [...]
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1894,11 +1894,11 @@
"analysis": {
"state": "not_affected",
"justification": "code_not_reachable",
- "detail": "CVE-2024-47561 (critical) is an arbitrary-code-execution
issue in the Apache Avro Java SDK: parsing\nan attacker-controlled Avro
**schema** can instantiate arbitrary classes (affects avro <
1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is
**not affected**:\n\n* **Solr does not use Apache Avro.** There [...]
+ "detail": "CVE-2024-47561 (critical) is an arbitrary-code-execution
issue in the Apache Avro Java SDK: parsing\nan attacker-controlled Avro
**schema** can instantiate arbitrary classes (affects avro <
1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is
**not affected**:\n\n* **Solr does not use Apache Avro.** There [...]
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1915,7 +1915,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1932,7 +1932,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1949,7 +1949,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1966,7 +1966,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -1983,7 +1983,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2000,7 +2000,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2017,7 +2017,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2034,7 +2034,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2051,7 +2051,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2068,7 +2068,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2085,7 +2085,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2102,7 +2102,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2119,7 +2119,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2136,7 +2136,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2153,7 +2153,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2170,7 +2170,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2187,7 +2187,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2204,7 +2204,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2221,7 +2221,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2238,7 +2238,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2255,7 +2255,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2272,7 +2272,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2289,7 +2289,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2306,7 +2306,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2323,7 +2323,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2340,7 +2340,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2357,7 +2357,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2374,7 +2374,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2391,7 +2391,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2408,7 +2408,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2425,7 +2425,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
},
@@ -2442,7 +2442,7 @@
},
"affects": [
{
- "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+ "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
}
]
}
diff --git a/output/vex.html b/output/vex.html
index 7fb0698ab..fe68553e6 100644
--- a/output/vex.html
+++ b/output/vex.html
@@ -663,10 +663,14 @@ avro < 1.11.3). Both require the application to feed
attacker-controlled Avro
own internal machinery, driven by administrator-supplied configuration, not
by untrusted request
input.</li>
</ul>
-<p>The affected range covers the 9.x line, where the optional Hadoop modules
transitively carry Avro
-1.9.2; Solr's own code path never invokes it. A scanner surfaces this as
<code>[email protected]</code> because Avro is
-shaded inside <code>hadoop-client-runtime-3.4.0.jar</code> in the
<code>hdfs</code> module (this is the form reported by
-SOLR-17900); it is the same non-reachable Hadoop transitive either way.</p>
+<p>The affected range covers Solr 9.0.0 – 9.10.1, where the optional Hadoop
modules transitively carry a
+vulnerable Avro (1.7.7 in <code>hadoop-client-runtime</code> 3.3.2 – 3.3.6,
then 1.9.2 in 3.4.0 – 3.4.1); Solr's
+own code path never invokes it. A scanner surfaces this as
<code>[email protected]</code> because Avro is shaded inside
+<code>hadoop-client-runtime</code> in the <code>hdfs</code> module (the form
reported by SOLR-17900). Unlike the other
+Hadoop-shaded CVEs from SOLR-17900, Avro stayed vulnerable all the way through
9.10.1: Solr 9.11
+(branch_9x) is the first fixed release, having upgraded to Hadoop 3.4.3, whose
<code>hadoop-client-runtime</code>
+shades Avro 1.11.4 (past both the 1.11.3 and 1.11.4 fixes). Solr 10.x ships no
<code>hadoop-client-runtime</code>.
+Either way it is the same non-reachable Hadoop transitive.</p>
<h4>References</h4>
<ul>
@@ -2303,7 +2307,7 @@ extraction out of Solr (the recommended architecture) or
replace the bundled
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 9.0.0-9.10.1</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 9.0.0-9.9.0</p>
</div>
</header>
@@ -2319,7 +2323,10 @@ integration — both the standalone copy in the
<code>hadoop-auth</code> module
path feeds attacker-controlled configuration to Commons Configuration, so the
recursive list-delimiter
parser cannot be driven by an adversary. This matches the existing assessment
of the other Commons
Configuration CVEs (CVE-2022-33980, CVE-2026-45205). The affected range spans
the releases whose
-Hadoop modules carry an affected commons-configuration2 (Solr 9.0.0 –
9.10.1).</p>
+Hadoop modules carry an affected commons-configuration2 — Solr 9.0.0 – 9.9.0
(<code>hadoop-client-runtime</code>
+3.3.2 – 3.4.0 shades commons-configuration2 ≤ 2.8.0; the standalone
<code>hadoop-auth</code> copy was already
+≥ 2.10.1, at 2.11.0, by 9.7.0). Solr 9.10.0 upgraded to Hadoop 3.4.1, whose
<code>hadoop-client-runtime</code>
+shades the fixed commons-configuration2 2.10.1, so 9.10.x onward is not
affected.</p>
<h4>References</h4>
<ul>
@@ -2339,7 +2346,7 @@ Hadoop modules carry an affected commons-configuration2
(Solr 9.0.0 – 9.10.1).
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 9.0.0-9.10.1</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 9.0.0-9.9.0</p>
</div>
</header>
@@ -2354,7 +2361,10 @@ format) is not part of any Solr request path. The
affected <code>commons-compres
module; Solr's HDFS-client usage does not feed untrusted Pack200 input to it,
and Solr's own use of
Commons Compress elsewhere does not invoke the Pack200 unpacker. The
vulnerable code path is therefore
not reached. The affected range spans the releases whose <code>hdfs</code>
module bundles an affected shaded
-commons-compress (Solr 9.0.0 – 9.10.1); Solr 10.x ships no
<code>hadoop-client-runtime</code>.</p>
+commons-compress — Solr 9.0.0 – 9.9.0 (<code>hadoop-client-runtime</code>
3.3.2 – 3.4.0, shading commons-compress
+≤ 1.24.0; the standalone copy in the <code>extraction</code> module was
already ≥ 1.26.0 by 9.7.0). Solr 9.10.0
+upgraded to Hadoop 3.4.1, whose <code>hadoop-client-runtime</code> shades the
fixed commons-compress 1.26.1, and
+Solr 10.x ships no <code>hadoop-client-runtime</code>, so neither is
affected.</p>
<h4>References</h4>
<ul>
@@ -2374,7 +2384,7 @@ commons-compress (Solr 9.0.0 – 9.10.1); Solr 10.x ships
no <code>hadoop-client
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 9.0.0-9.10.1</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 9.0.0-9.9.0</p>
</div>
</header>
@@ -2389,7 +2399,9 @@ where Hadoop may use it for name resolution. Solr uses
the HDFS module only as a
connects to operator-configured HDFS NameNode/DataNode hosts, not
attacker-controlled names, and it
does not rely on dnsjava's DNSSEC validation to make any security decision.
The vulnerable resolver
path is therefore not reached. The affected range spans the releases whose
<code>hdfs</code> module bundles an
-affected shaded dnsjava (Solr 9.0.0 – 9.10.1); Solr 10.x ships no
<code>hadoop-client-runtime</code>.</p>
+affected shaded dnsjava — Solr 9.0.0 – 9.9.0
(<code>hadoop-client-runtime</code> 3.3.2 – 3.4.0, shading dnsjava
+≤ 3.4.0). Solr 9.10.0 upgraded to Hadoop 3.4.1, whose
<code>hadoop-client-runtime</code> shades the fixed dnsjava
+3.6.1, and Solr 10.x ships no <code>hadoop-client-runtime</code>, so neither
is affected.</p>
<h4>References</h4>
<ul>
@@ -2448,7 +2460,7 @@ extraction in a separate Tika service, or replace
<code>modules/extraction/lib/a
<strong>Status:</strong>
<span class="cdx-not-affected">not_affected</span>
</p>
- <p class="subheader"><strong>Affected Solr
versions:</strong> 9.0.0-9.10.1</p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 9.0.0-9.9.0</p>
</div>
</header>
@@ -2462,8 +2474,10 @@ application parses attacker-supplied JOSE/JWT input with
Nimbus.</p>
scanner flags (<code>[email protected]</code>) is shaded inside
<code>hadoop-client-runtime</code> in the optional
<code>hdfs</code> module and is only used by Hadoop's own internal auth
machinery — Solr never routes an
untrusted, externally-supplied JOSE object to it. The vulnerable parser is
therefore not reached. The
-affected range spans the releases whose <code>hdfs</code> module bundles the
affected shaded Nimbus (Solr
-9.0.0 – 9.10.1); Solr 10.x ships no <code>hadoop-client-runtime</code>.</p>
+affected range spans the releases whose <code>hdfs</code> module bundles an
affected shaded Nimbus — Solr
+9.0.0 – 9.9.0 (<code>hadoop-client-runtime</code> 3.3.2 – 3.4.0, shading
Nimbus ≤ 9.31). Solr 9.10.0 upgraded to
+Hadoop 3.4.1, whose <code>hadoop-client-runtime</code> shades the fixed Nimbus
9.37.2, and Solr 10.x ships no
+<code>hadoop-client-runtime</code>, so neither is affected.</p>
<h4>References</h4>
<ul>