This is an automated email from the ASF dual-hosted git repository.

github-actions[bot] pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/solr-site.git


The following commit(s) were added to refs/heads/asf-staging by this push:
     new fdd26c740 Commit build products
fdd26c740 is described below

commit fdd26c740ad998ab6d3f9086aad2a5f63cf9180c
Author: Build Pelican (action) <[email protected]>
AuthorDate: Thu Aug 13 01:35:46 2026 +0000

    Commit build products
---
 output/feeds/all.atom.xml            |  40 ++---
 output/feeds/solr/vex.atom.xml       |  16 +-
 output/security-dependency-cves.html |   9 +
 output/solr.openvex.json             |  15 ++
 output/solr.vex.json                 | 311 ++++++++++++++++++-----------------
 output/vex.html                      |  36 ++++
 6 files changed, 255 insertions(+), 172 deletions(-)

diff --git a/output/feeds/all.atom.xml b/output/feeds/all.atom.xml
index 77d32f7f2..ad9dc40da 100644
--- a/output/feeds/all.atom.xml
+++ b/output/feeds/all.atom.xml
@@ -1500,7 +1500,21 @@ Damon Toey (reporter)&lt;/p&gt;
 &lt;p&gt;Please refer to the Upgrade Notes in the Solr Ref Guide for 
information on upgrading from previous Solr versions:&lt;/p&gt;
 &lt;p&gt;&lt;a 
href="https://solr.apache.org/guide/solr/9_10/upgrade-notes/solr-upgrade-notes.html"&gt;https://solr.apache.org/guide/solr/9_10/upgrade-notes/solr-upgrade-notes.html&lt;/a&gt;&lt;/p&gt;
 &lt;p&gt;Please read CHANGELOG.md for a full list of new features, changes and 
bugfixes:&lt;/p&gt;
-&lt;p&gt;&lt;a 
href="https://solr.apache.org/9_10_0/changes/Changes.html"&gt;https://solr.apache.org/9_10_0/changes/Changes.html&lt;/a&gt;&lt;/p&gt;</content><category
 term="solr/news"/></entry><entry><title>Bouncy Castle (bcprov): LDAP CertStore 
injection, EC/Ed25519 DoS, and RSA/TLS timing side-channel</title><link 
href="/cve-2023-33201.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 Developers</name> [...]
+&lt;p&gt;&lt;a 
href="https://solr.apache.org/9_10_0/changes/Changes.html"&gt;https://solr.apache.org/9_10_0/changes/Changes.html&lt;/a&gt;&lt;/p&gt;</content><category
 term="solr/news"/></entry><entry><title>Apache Thrift: server-side 
memory-exhaustion DoS via crafted short messages</title><link 
href="/cve-2020-13949.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 Developers</name></author><id>tag:None, [...]
+specially-crafted short messages that cause a Thrift 
&lt;strong&gt;server&lt;/strong&gt; to allocate a large amount of memory,
+potentially exhausting it (affects &lt;code&gt;libthrift&lt;/code&gt; 0.9.3 – 
0.13.0, fixed in 0.14.0). It is reachable only
+by …&lt;/p&gt;</summary><content type="html">&lt;p&gt;CVE-2020-13949 is a 
denial-of-service issue in Apache Thrift: a malicious RPC 
&lt;strong&gt;client&lt;/strong&gt; can send
+specially-crafted short messages that cause a Thrift 
&lt;strong&gt;server&lt;/strong&gt; to allocate a large amount of memory,
+potentially exhausting it (affects &lt;code&gt;libthrift&lt;/code&gt; 0.9.3 – 
0.13.0, fixed in 0.14.0). It is reachable only
+by an application that runs a Thrift server accepting messages from untrusted 
clients.&lt;/p&gt;
+&lt;p&gt;Solr is &lt;strong&gt;not affected&lt;/strong&gt;. 
&lt;code&gt;libthrift&lt;/code&gt; is bundled only by the optional Jaeger 
distributed-tracing
+integration, where Solr uses Thrift purely as a 
&lt;strong&gt;client&lt;/strong&gt; to export spans to an operator-configured
+Jaeger collector — it never runs a Thrift RPC server that accepts untrusted 
incoming messages. The
+vulnerable server-side allocation path is therefore never reached.&lt;/p&gt;
+&lt;p&gt;Solr shipped an affected &lt;code&gt;libthrift&lt;/code&gt; in the 
8.x line — 0.12.0 (8.2.0) and 0.13.0 (8.5.0 – 8.8.1),
+both ≤ 0.13.0 — so the affected range is 8.2.0 – 8.8.1. Solr 9.0.0 upgraded to 
&lt;code&gt;libthrift&lt;/code&gt; 0.14.1
+(and later 0.15.0), which are past the 0.14.0 fix, so no 9.x or 10.x release 
is affected. (The Solr
+8.x line is end of life.)&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Bouncy Castle (bcprov): LDAP CertStore 
injection, EC/Ed25519 DoS, and RSA/TLS timing side-channel</title><link 
href="/cve-2023-33201.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2023-33201.html</id><summary
 type="html">&lt;p&gt;Four vulnerabilities in th [...]
 each in a distinct crypto operation:&lt;/p&gt;
 &lt;ul&gt;
 &lt;li&gt;&lt;strong&gt;CVE-2023-33201&lt;/strong&gt; — LDAP injection in the 
X.509 &lt;code&gt;CertStore&lt;/code&gt; (fixed in 1.74); requires using Bouncy
@@ -2396,26 +2410,4 @@ in Solr 8.1.0 (2.4.0) and shipped an affected version — 
2.4.0, then 2.7.0, the
 &lt;p&gt;&lt;a 
href="https://solr.apache.org/guide/operator/latest/upgrade-notes/upgrade-notes.html"&gt;https://solr.apache.org/guide/operator/latest/upgrade-notes/upgrade-notes.html&lt;/a&gt;&lt;/p&gt;
 &lt;p&gt;For the most exhaustive list, see the change log on ArtifactHub or 
view the git history in the solr-operator repo.&lt;/p&gt;
 &lt;p&gt;&lt;a 
href="https://artifacthub.io/packages/helm/apache-solr/solr-operator?modal=changelog"&gt;https://artifacthub.io/packages/helm/apache-solr/solr-operator?modal=changelog&lt;/a&gt;&lt;/p&gt;
-&lt;p&gt;&lt;a 
href="https://github.com/apache/solr-operator/releases/tag/v0.7.0"&gt;https://github.com/apache/solr-operator/releases/tag/v0.7.0&lt;/a&gt;&lt;/p&gt;</content><category
 term="solr/operator/news"/></entry><entry><title>Apache Solr™ 9.2.0 
available</title><link href="/apache-solrtm-920-available.html" 
rel="alternate"/><published>2023-03-24T00:00:00+00:00</published><updated>2023-03-24T00:00:00+00:00</updated><author><name>Solr
 Developers</name></author><id>tag:None,2023-03-2 [...]
-&lt;p&gt;Solr is the popular, blazing fast, open source NoSQL search platform 
from the Apache Solr project. Its major features include powerful full-text 
search, hit highlighting, faceted search, dynamic clustering, database 
integration, rich document handling, and …&lt;/p&gt;</summary><content 
type="html">&lt;p&gt;The Solr PMC is pleased to announce the release of Apache 
Solr 9.2.0.&lt;/p&gt;
-&lt;p&gt;Solr is the popular, blazing fast, open source NoSQL search platform 
from the Apache Solr project. Its major features include powerful full-text 
search, hit highlighting, faceted search, dynamic clustering, database 
integration, rich document handling, and geospatial search. Solr is highly 
scalable, providing fault tolerant distributed search and indexing, and powers 
the search and navigation features of many of the world's largest internet 
sites.&lt;/p&gt;
-&lt;p&gt;Solr 9.2.0 is available for immediate download at:&lt;/p&gt;
-&lt;p&gt;&lt;a 
href="https://solr.apache.org/downloads.html"&gt;https://solr.apache.org/downloads.html&lt;/a&gt;&lt;/p&gt;
-&lt;h3 id="solr-920-release-highlights"&gt;Solr 9.2.0 Release Highlights:&lt;a 
class="headerlink" href="#solr-920-release-highlights" title="Permanent 
link"&gt;&amp;para;&lt;/a&gt;&lt;/h3&gt;
-&lt;ul&gt;
-&lt;li&gt;Solr has upgraded to use Jetty 10 instead of Jetty 9.&lt;/li&gt;
-&lt;li&gt;Solr now includes an opentracing module, with support for OTEL 
tracing in OTLP  format using gRPC.&lt;ul&gt;
-&lt;li&gt;This module is meant to replace the jaegertracer-configurator 
module, which has been deprecated. &lt;/li&gt;
-&lt;/ul&gt;
-&lt;/li&gt;
-&lt;li&gt;The base operating system of the Solr Docker image has been upgraded 
to Ubuntu 22 (Jammy).&lt;/li&gt;
-&lt;li&gt;Streaming Expressions have been moved out of Solrj core into its own 
module called solrj-streaming.&lt;/li&gt;
-&lt;li&gt;SolrJ Solr clients now use a builder/setter pattern to enable easier 
setup.&lt;/li&gt;
-&lt;li&gt;Solr ConfigSet management has been optimized to improve the startup 
time of nodes with multiple replicas.&lt;/li&gt;
-&lt;li&gt;SolrJ can again be used with the default Java truststore.&lt;/li&gt;
-&lt;li&gt;The "Films" example has been updated to demonstrate Dense Vector 
search.&lt;/li&gt;
-&lt;/ul&gt;
-&lt;p&gt;Please refer to the Upgrade Notes in the Solr Ref Guide for 
information on upgrading from previous Solr versions:&lt;/p&gt;
-&lt;p&gt;&lt;a 
href="https://solr.apache.org/guide/solr/9_2/upgrade-notes/solr-upgrade-notes.html"&gt;https://solr.apache.org/guide/solr/9_2/upgrade-notes/solr-upgrade-notes.html&lt;/a&gt;&lt;/p&gt;
-&lt;p&gt;Please read CHANGES.txt for a full list of new features, changes and 
bugfixes:&lt;/p&gt;
-&lt;p&gt;&lt;a 
href="https://solr.apache.org/9_2_0/changes/Changes.html"&gt;https://solr.apache.org/9_2_0/changes/Changes.html&lt;/a&gt;&lt;/p&gt;</content><category
 term="solr/news"/></entry></feed>
\ No newline at end of file
+&lt;p&gt;&lt;a 
href="https://github.com/apache/solr-operator/releases/tag/v0.7.0"&gt;https://github.com/apache/solr-operator/releases/tag/v0.7.0&lt;/a&gt;&lt;/p&gt;</content><category
 term="solr/operator/news"/></entry></feed>
\ No newline at end of file
diff --git a/output/feeds/solr/vex.atom.xml b/output/feeds/solr/vex.atom.xml
index 050295bf0..7adc8d16d 100644
--- a/output/feeds/solr/vex.atom.xml
+++ b/output/feeds/solr/vex.atom.xml
@@ -1268,7 +1268,21 @@ is referenced only inside Log4j's own JARs.
 Neither Solr nor any of its bundled dependencies ever constructs or logs such 
a message.&lt;/p&gt;
 &lt;p&gt;Because no shipped code can hand a triggering value to the layout,
 the vulnerable code path cannot be reached regardless of the configured layout,
-and the Solr community considers this vulnerability 
&lt;strong&gt;non-exploitable&lt;/strong&gt; in the binary 
distribution.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Bouncy Castle (bcprov): LDAP CertStore 
injection, EC/Ed25519 DoS, and RSA/TLS timing side-channel</title><link 
href="/cve-2023-33201.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 Developers</name></author><id>ta [...]
+and the Solr community considers this vulnerability 
&lt;strong&gt;non-exploitable&lt;/strong&gt; in the binary 
distribution.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache Thrift: server-side 
memory-exhaustion DoS via crafted short messages</title><link 
href="/cve-2020-13949.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 Developers</name></author><id>tag:None,2025-09-07:/cve [...]
+specially-crafted short messages that cause a Thrift 
&lt;strong&gt;server&lt;/strong&gt; to allocate a large amount of memory,
+potentially exhausting it (affects &lt;code&gt;libthrift&lt;/code&gt; 0.9.3 – 
0.13.0, fixed in 0.14.0). It is reachable only
+by …&lt;/p&gt;</summary><content type="html">&lt;p&gt;CVE-2020-13949 is a 
denial-of-service issue in Apache Thrift: a malicious RPC 
&lt;strong&gt;client&lt;/strong&gt; can send
+specially-crafted short messages that cause a Thrift 
&lt;strong&gt;server&lt;/strong&gt; to allocate a large amount of memory,
+potentially exhausting it (affects &lt;code&gt;libthrift&lt;/code&gt; 0.9.3 – 
0.13.0, fixed in 0.14.0). It is reachable only
+by an application that runs a Thrift server accepting messages from untrusted 
clients.&lt;/p&gt;
+&lt;p&gt;Solr is &lt;strong&gt;not affected&lt;/strong&gt;. 
&lt;code&gt;libthrift&lt;/code&gt; is bundled only by the optional Jaeger 
distributed-tracing
+integration, where Solr uses Thrift purely as a 
&lt;strong&gt;client&lt;/strong&gt; to export spans to an operator-configured
+Jaeger collector — it never runs a Thrift RPC server that accepts untrusted 
incoming messages. The
+vulnerable server-side allocation path is therefore never reached.&lt;/p&gt;
+&lt;p&gt;Solr shipped an affected &lt;code&gt;libthrift&lt;/code&gt; in the 
8.x line — 0.12.0 (8.2.0) and 0.13.0 (8.5.0 – 8.8.1),
+both ≤ 0.13.0 — so the affected range is 8.2.0 – 8.8.1. Solr 9.0.0 upgraded to 
&lt;code&gt;libthrift&lt;/code&gt; 0.14.1
+(and later 0.15.0), which are past the 0.14.0 fix, so no 9.x or 10.x release 
is affected. (The Solr
+8.x line is end of life.)&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Bouncy Castle (bcprov): LDAP CertStore 
injection, EC/Ed25519 DoS, and RSA/TLS timing side-channel</title><link 
href="/cve-2023-33201.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2023-33201.html</id><summary
 type="html">&lt;p&gt;Four vulnerabilities in th [...]
 each in a distinct crypto operation:&lt;/p&gt;
 &lt;ul&gt;
 &lt;li&gt;&lt;strong&gt;CVE-2023-33201&lt;/strong&gt; — LDAP injection in the 
X.509 &lt;code&gt;CertStore&lt;/code&gt; (fixed in 1.74); requires using Bouncy
diff --git a/output/security-dependency-cves.html 
b/output/security-dependency-cves.html
index 7d8b3831c..4c8f95cb9 100644
--- a/output/security-dependency-cves.html
+++ b/output/security-dependency-cves.html
@@ -686,6 +686,15 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     </tr>
     <tr>
       <td>
+<a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13949";>CVE-2020-13949</a>   
   </td>
+      <td>8.2.0-8.8.1</td>
+      <td>
+          libthrift-0.13.0.jar      </td>
+      <td><span class="cdx-not-affected">not affected</span></td>
+      <td><a href="/vex.html#cve-2020-13949">Apache Thrift: server-side 
memory-exhaustion DoS via crafted short messages</a></td>
+    </tr>
+    <tr>
+      <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924";>CVE-2025-48924</a>   
   </td>
       <td>9.0.0-9.9.0</td>
       <td>
diff --git a/output/solr.openvex.json b/output/solr.openvex.json
index 74e33ae8d..e5e051e94 100644
--- a/output/solr.openvex.json
+++ b/output/solr.openvex.json
@@ -1496,6 +1496,21 @@
       "impact_statement": "CVE-2025-48924 is an uncontrolled-recursion issue 
in Apache Commons Lang's\n`ClassUtils.getClass(...)`: a very long, 
deeply-nested class name can exhaust the stack and\nthrow `StackOverflowError`. 
It affects `commons-lang3` from 3.0 up to (but not including) 3.18.0,\nso 
dependency scanners flag the `commons-lang3` JAR bundled in Solr 9.x (which 
ships versions\n3.12.0 through 3.15.0 across the 9.0\u20139.9 line).\n\nSolr is 
**not affected**. The vulnerable `Clas [...]
       "status_notes": "Affected Apache Solr versions: 9.0.0-9.9.0."
     },
+    {
+      "vulnerability": {
+        "name": "CVE-2020-13949"
+      },
+      "products": [
+        {
+          "@id": "libthrift-0.13.0.jar"
+        }
+      ],
+      "status": "not_affected",
+      "timestamp": "2025-09-07T00:00:00Z",
+      "justification": "vulnerable_code_not_in_execute_path",
+      "impact_statement": "CVE-2020-13949 is a denial-of-service issue in 
Apache Thrift: a malicious RPC **client** can send\nspecially-crafted short 
messages that cause a Thrift **server** to allocate a large amount of 
memory,\npotentially exhausting it (affects `libthrift` 0.9.3 \u2013 0.13.0, 
fixed in 0.14.0). It is reachable only\nby an application that runs a Thrift 
server accepting messages from untrusted clients.\n\nSolr is **not affected**. 
`libthrift` is bundled only by the opti [...]
+      "status_notes": "Affected Apache Solr versions: 8.2.0-8.8.1."
+    },
     {
       "vulnerability": {
         "name": "CVE-2023-33201"
diff --git a/output/solr.vex.json b/output/solr.vex.json
index 80c3d96fe..550808ba8 100644
--- a/output/solr.vex.json
+++ b/output/solr.vex.json
@@ -7,7 +7,7 @@
       "name": "solr",
       "version": "SNAPSHOT",
       "type": "application",
-      "bom-ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+      "bom-ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
     }
   },
   "vulnerabilities": [
@@ -23,7 +23,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -39,7 +39,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -55,7 +55,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -71,7 +71,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -87,7 +87,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -103,7 +103,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -119,7 +119,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -135,7 +135,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -151,7 +151,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -167,7 +167,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -183,7 +183,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -199,7 +199,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -215,7 +215,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -231,7 +231,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -247,7 +247,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -263,7 +263,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -279,7 +279,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -295,7 +295,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -311,7 +311,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -327,7 +327,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -343,7 +343,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -359,7 +359,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -375,7 +375,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -391,7 +391,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -407,7 +407,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -423,7 +423,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -439,7 +439,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -455,7 +455,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -471,7 +471,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -487,7 +487,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -503,7 +503,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -519,7 +519,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -535,7 +535,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -551,7 +551,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -567,7 +567,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -583,7 +583,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -599,7 +599,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -615,7 +615,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -631,7 +631,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -647,7 +647,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -663,7 +663,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -679,7 +679,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -695,7 +695,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -711,7 +711,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -727,7 +727,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -743,7 +743,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -759,7 +759,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -775,7 +775,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -791,7 +791,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -807,7 +807,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -823,7 +823,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -839,7 +839,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -855,7 +855,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -871,7 +871,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -887,7 +887,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -903,7 +903,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -919,7 +919,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -935,7 +935,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -951,7 +951,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -970,7 +970,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -986,7 +986,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1002,7 +1002,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1018,7 +1018,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1037,7 +1037,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1053,7 +1053,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1070,7 +1070,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1087,7 +1087,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1104,7 +1104,24 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
+        }
+      ]
+    },
+    {
+      "id": "CVE-2020-13949",
+      "source": {
+        "name": "NVD",
+        "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13949";
+      },
+      "analysis": {
+        "state": "not_affected",
+        "justification": "code_not_reachable",
+        "detail": "CVE-2020-13949 is a denial-of-service issue in Apache 
Thrift: a malicious RPC **client** can send\nspecially-crafted short messages 
that cause a Thrift **server** to allocate a large amount of 
memory,\npotentially exhausting it (affects `libthrift` 0.9.3 \u2013 0.13.0, 
fixed in 0.14.0). It is reachable only\nby an application that runs a Thrift 
server accepting messages from untrusted clients.\n\nSolr is **not affected**. 
`libthrift` is bundled only by the optional Jae [...]
+      },
+      "affects": [
+        {
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1121,7 +1138,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1138,7 +1155,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1155,7 +1172,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1172,7 +1189,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1189,7 +1206,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1206,7 +1223,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1223,7 +1240,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1240,7 +1257,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1257,7 +1274,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1274,7 +1291,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1291,7 +1308,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1308,7 +1325,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1325,7 +1342,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1342,7 +1359,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1359,7 +1376,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1376,7 +1393,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1396,7 +1413,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1416,7 +1433,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1436,7 +1453,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1453,7 +1470,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1473,7 +1490,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1490,7 +1507,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1507,7 +1524,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1524,7 +1541,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1541,7 +1558,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1558,7 +1575,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1575,7 +1592,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1592,7 +1609,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1609,7 +1626,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1626,7 +1643,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1643,7 +1660,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1660,7 +1677,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1677,7 +1694,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1694,7 +1711,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1711,7 +1728,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1728,7 +1745,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1745,7 +1762,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1762,7 +1779,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1779,7 +1796,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1796,7 +1813,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1813,7 +1830,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1830,7 +1847,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1847,7 +1864,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1864,7 +1881,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1881,7 +1898,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1898,7 +1915,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1915,7 +1932,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1932,7 +1949,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1949,7 +1966,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1966,7 +1983,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -1983,7 +2000,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2000,7 +2017,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2017,7 +2034,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2034,7 +2051,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2051,7 +2068,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2068,7 +2085,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2085,7 +2102,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2102,7 +2119,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2119,7 +2136,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2136,7 +2153,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2153,7 +2170,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2170,7 +2187,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2187,7 +2204,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2204,7 +2221,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2221,7 +2238,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2238,7 +2255,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2255,7 +2272,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2272,7 +2289,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2289,7 +2306,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2306,7 +2323,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2323,7 +2340,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2340,7 +2357,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2357,7 +2374,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2374,7 +2391,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2391,7 +2408,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2408,7 +2425,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2425,7 +2442,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     },
@@ -2442,7 +2459,7 @@
       },
       "affects": [
         {
-          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+          "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
         }
       ]
     }
diff --git a/output/vex.html b/output/vex.html
index fe68553e6..31a4bd354 100644
--- a/output/vex.html
+++ b/output/vex.html
@@ -2539,6 +2539,42 @@ module, fixed to 1.78.1 in 9.7; the same not-affected 
reasoning applies.)</p>
                         <li>CVE: <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2023-33201";>CVE-2023-33201</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2024-29857";>CVE-2024-29857</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2024-30171";>CVE-2024-30171</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2024-30172";>CVE-2024-30172</a></li>
                 </ul>
             </article>
+            <article id="cve-2020-13949" class="post panel radius">
+                <header class="post-header">
+                    <h3 class="title"><a 
href="https://nvd.nist.gov/vuln/detail/CVE-2020-13949";>CVE-2020-13949</a>, 
Apache Thrift: server-side memory-exhaustion DoS via crafted short messages</h3>
+                    <div class="panel callout">
+                            <p class="subheader">
+                                <strong>Published:</strong>
+                                <time 
datetime="2025-09-07T00:00:00+00:00">2025-09-07</time>
+                            </p>
+                        <p class="subheader">
+                            <strong>Status:</strong>
+                            <span class="cdx-not-affected">not_affected</span>
+                        </p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 8.2.0-8.8.1</p>
+                    </div>
+                </header>
+
+                <h4>Description</h4>
+                <p>CVE-2020-13949 is a denial-of-service issue in Apache 
Thrift: a malicious RPC <strong>client</strong> can send
+specially-crafted short messages that cause a Thrift <strong>server</strong> 
to allocate a large amount of memory,
+potentially exhausting it (affects <code>libthrift</code> 0.9.3 – 0.13.0, 
fixed in 0.14.0). It is reachable only
+by an application that runs a Thrift server accepting messages from untrusted 
clients.</p>
+<p>Solr is <strong>not affected</strong>. <code>libthrift</code> is bundled 
only by the optional Jaeger distributed-tracing
+integration, where Solr uses Thrift purely as a <strong>client</strong> to 
export spans to an operator-configured
+Jaeger collector — it never runs a Thrift RPC server that accepts untrusted 
incoming messages. The
+vulnerable server-side allocation path is therefore never reached.</p>
+<p>Solr shipped an affected <code>libthrift</code> in the 8.x line — 0.12.0 
(8.2.0) and 0.13.0 (8.5.0 – 8.8.1),
+both ≤ 0.13.0 — so the affected range is 8.2.0 – 8.8.1. Solr 9.0.0 upgraded to 
<code>libthrift</code> 0.14.1
+(and later 0.15.0), which are past the 0.14.0 fix, so no 9.x or 10.x release 
is affected. (The Solr
+8.x line is end of life.)</p>
+
+                <h4>References</h4>
+                <ul>
+                        <li>JIRA: <a 
href="https://issues.apache.org/jira/browse/SOLR-15507";>SOLR-15507</a></li>
+                        <li>CVE: <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2020-13949";>CVE-2020-13949</a></li>
+                </ul>
+            </article>
             <article id="cve-2025-48924" class="post panel radius">
                 <header class="post-header">
                     <h3 class="title"><a 
href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924";>CVE-2025-48924</a>, 
Apache Commons Lang: uncontrolled recursion in ClassUtils.getClass</h3>

Reply via email to