This is an automated email from the ASF dual-hosted git repository.
github-actions[bot] pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/solr-site.git
The following commit(s) were added to refs/heads/asf-staging by this push:
new fdd26c740 Commit build products
fdd26c740 is described below
commit fdd26c740ad998ab6d3f9086aad2a5f63cf9180c
Author: Build Pelican (action) <[email protected]>
AuthorDate: Thu Aug 13 01:35:46 2026 +0000
Commit build products
---
output/feeds/all.atom.xml | 40 ++---
output/feeds/solr/vex.atom.xml | 16 +-
output/security-dependency-cves.html | 9 +
output/solr.openvex.json | 15 ++
output/solr.vex.json | 311 ++++++++++++++++++-----------------
output/vex.html | 36 ++++
6 files changed, 255 insertions(+), 172 deletions(-)
diff --git a/output/feeds/all.atom.xml b/output/feeds/all.atom.xml
index 77d32f7f2..ad9dc40da 100644
--- a/output/feeds/all.atom.xml
+++ b/output/feeds/all.atom.xml
@@ -1500,7 +1500,21 @@ Damon Toey (reporter)</p>
<p>Please refer to the Upgrade Notes in the Solr Ref Guide for
information on upgrading from previous Solr versions:</p>
<p><a
href="https://solr.apache.org/guide/solr/9_10/upgrade-notes/solr-upgrade-notes.html">https://solr.apache.org/guide/solr/9_10/upgrade-notes/solr-upgrade-notes.html</a></p>
<p>Please read CHANGELOG.md for a full list of new features, changes and
bugfixes:</p>
-<p><a
href="https://solr.apache.org/9_10_0/changes/Changes.html">https://solr.apache.org/9_10_0/changes/Changes.html</a></p></content><category
term="solr/news"/></entry><entry><title>Bouncy Castle (bcprov): LDAP CertStore
injection, EC/Ed25519 DoS, and RSA/TLS timing side-channel</title><link
href="/cve-2023-33201.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name> [...]
+<p><a
href="https://solr.apache.org/9_10_0/changes/Changes.html">https://solr.apache.org/9_10_0/changes/Changes.html</a></p></content><category
term="solr/news"/></entry><entry><title>Apache Thrift: server-side
memory-exhaustion DoS via crafted short messages</title><link
href="/cve-2020-13949.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None, [...]
+specially-crafted short messages that cause a Thrift
<strong>server</strong> to allocate a large amount of memory,
+potentially exhausting it (affects <code>libthrift</code> 0.9.3 –
0.13.0, fixed in 0.14.0). It is reachable only
+by …</p></summary><content type="html"><p>CVE-2020-13949 is a
denial-of-service issue in Apache Thrift: a malicious RPC
<strong>client</strong> can send
+specially-crafted short messages that cause a Thrift
<strong>server</strong> to allocate a large amount of memory,
+potentially exhausting it (affects <code>libthrift</code> 0.9.3 –
0.13.0, fixed in 0.14.0). It is reachable only
+by an application that runs a Thrift server accepting messages from untrusted
clients.</p>
+<p>Solr is <strong>not affected</strong>.
<code>libthrift</code> is bundled only by the optional Jaeger
distributed-tracing
+integration, where Solr uses Thrift purely as a
<strong>client</strong> to export spans to an operator-configured
+Jaeger collector — it never runs a Thrift RPC server that accepts untrusted
incoming messages. The
+vulnerable server-side allocation path is therefore never reached.</p>
+<p>Solr shipped an affected <code>libthrift</code> in the
8.x line — 0.12.0 (8.2.0) and 0.13.0 (8.5.0 – 8.8.1),
+both ≤ 0.13.0 — so the affected range is 8.2.0 – 8.8.1. Solr 9.0.0 upgraded to
<code>libthrift</code> 0.14.1
+(and later 0.15.0), which are past the 0.14.0 fix, so no 9.x or 10.x release
is affected. (The Solr
+8.x line is end of life.)</p></content><category
term="solr/vex"/></entry><entry><title>Bouncy Castle (bcprov): LDAP CertStore
injection, EC/Ed25519 DoS, and RSA/TLS timing side-channel</title><link
href="/cve-2023-33201.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2023-33201.html</id><summary
type="html"><p>Four vulnerabilities in th [...]
each in a distinct crypto operation:</p>
<ul>
<li><strong>CVE-2023-33201</strong> — LDAP injection in the
X.509 <code>CertStore</code> (fixed in 1.74); requires using Bouncy
@@ -2396,26 +2410,4 @@ in Solr 8.1.0 (2.4.0) and shipped an affected version —
2.4.0, then 2.7.0, the
<p><a
href="https://solr.apache.org/guide/operator/latest/upgrade-notes/upgrade-notes.html">https://solr.apache.org/guide/operator/latest/upgrade-notes/upgrade-notes.html</a></p>
<p>For the most exhaustive list, see the change log on ArtifactHub or
view the git history in the solr-operator repo.</p>
<p><a
href="https://artifacthub.io/packages/helm/apache-solr/solr-operator?modal=changelog">https://artifacthub.io/packages/helm/apache-solr/solr-operator?modal=changelog</a></p>
-<p><a
href="https://github.com/apache/solr-operator/releases/tag/v0.7.0">https://github.com/apache/solr-operator/releases/tag/v0.7.0</a></p></content><category
term="solr/operator/news"/></entry><entry><title>Apache Solr™ 9.2.0
available</title><link href="/apache-solrtm-920-available.html"
rel="alternate"/><published>2023-03-24T00:00:00+00:00</published><updated>2023-03-24T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2023-03-2 [...]
-<p>Solr is the popular, blazing fast, open source NoSQL search platform
from the Apache Solr project. Its major features include powerful full-text
search, hit highlighting, faceted search, dynamic clustering, database
integration, rich document handling, and …</p></summary><content
type="html"><p>The Solr PMC is pleased to announce the release of Apache
Solr 9.2.0.</p>
-<p>Solr is the popular, blazing fast, open source NoSQL search platform
from the Apache Solr project. Its major features include powerful full-text
search, hit highlighting, faceted search, dynamic clustering, database
integration, rich document handling, and geospatial search. Solr is highly
scalable, providing fault tolerant distributed search and indexing, and powers
the search and navigation features of many of the world's largest internet
sites.</p>
-<p>Solr 9.2.0 is available for immediate download at:</p>
-<p><a
href="https://solr.apache.org/downloads.html">https://solr.apache.org/downloads.html</a></p>
-<h3 id="solr-920-release-highlights">Solr 9.2.0 Release Highlights:<a
class="headerlink" href="#solr-920-release-highlights" title="Permanent
link">&para;</a></h3>
-<ul>
-<li>Solr has upgraded to use Jetty 10 instead of Jetty 9.</li>
-<li>Solr now includes an opentracing module, with support for OTEL
tracing in OTLP format using gRPC.<ul>
-<li>This module is meant to replace the jaegertracer-configurator
module, which has been deprecated. </li>
-</ul>
-</li>
-<li>The base operating system of the Solr Docker image has been upgraded
to Ubuntu 22 (Jammy).</li>
-<li>Streaming Expressions have been moved out of Solrj core into its own
module called solrj-streaming.</li>
-<li>SolrJ Solr clients now use a builder/setter pattern to enable easier
setup.</li>
-<li>Solr ConfigSet management has been optimized to improve the startup
time of nodes with multiple replicas.</li>
-<li>SolrJ can again be used with the default Java truststore.</li>
-<li>The "Films" example has been updated to demonstrate Dense Vector
search.</li>
-</ul>
-<p>Please refer to the Upgrade Notes in the Solr Ref Guide for
information on upgrading from previous Solr versions:</p>
-<p><a
href="https://solr.apache.org/guide/solr/9_2/upgrade-notes/solr-upgrade-notes.html">https://solr.apache.org/guide/solr/9_2/upgrade-notes/solr-upgrade-notes.html</a></p>
-<p>Please read CHANGES.txt for a full list of new features, changes and
bugfixes:</p>
-<p><a
href="https://solr.apache.org/9_2_0/changes/Changes.html">https://solr.apache.org/9_2_0/changes/Changes.html</a></p></content><category
term="solr/news"/></entry></feed>
\ No newline at end of file
+<p><a
href="https://github.com/apache/solr-operator/releases/tag/v0.7.0">https://github.com/apache/solr-operator/releases/tag/v0.7.0</a></p></content><category
term="solr/operator/news"/></entry></feed>
\ No newline at end of file
diff --git a/output/feeds/solr/vex.atom.xml b/output/feeds/solr/vex.atom.xml
index 050295bf0..7adc8d16d 100644
--- a/output/feeds/solr/vex.atom.xml
+++ b/output/feeds/solr/vex.atom.xml
@@ -1268,7 +1268,21 @@ is referenced only inside Log4j's own JARs.
Neither Solr nor any of its bundled dependencies ever constructs or logs such
a message.</p>
<p>Because no shipped code can hand a triggering value to the layout,
the vulnerable code path cannot be reached regardless of the configured layout,
-and the Solr community considers this vulnerability
<strong>non-exploitable</strong> in the binary
distribution.</p></content><category
term="solr/vex"/></entry><entry><title>Bouncy Castle (bcprov): LDAP CertStore
injection, EC/Ed25519 DoS, and RSA/TLS timing side-channel</title><link
href="/cve-2023-33201.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>ta [...]
+and the Solr community considers this vulnerability
<strong>non-exploitable</strong> in the binary
distribution.</p></content><category
term="solr/vex"/></entry><entry><title>Apache Thrift: server-side
memory-exhaustion DoS via crafted short messages</title><link
href="/cve-2020-13949.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve [...]
+specially-crafted short messages that cause a Thrift
<strong>server</strong> to allocate a large amount of memory,
+potentially exhausting it (affects <code>libthrift</code> 0.9.3 –
0.13.0, fixed in 0.14.0). It is reachable only
+by …</p></summary><content type="html"><p>CVE-2020-13949 is a
denial-of-service issue in Apache Thrift: a malicious RPC
<strong>client</strong> can send
+specially-crafted short messages that cause a Thrift
<strong>server</strong> to allocate a large amount of memory,
+potentially exhausting it (affects <code>libthrift</code> 0.9.3 –
0.13.0, fixed in 0.14.0). It is reachable only
+by an application that runs a Thrift server accepting messages from untrusted
clients.</p>
+<p>Solr is <strong>not affected</strong>.
<code>libthrift</code> is bundled only by the optional Jaeger
distributed-tracing
+integration, where Solr uses Thrift purely as a
<strong>client</strong> to export spans to an operator-configured
+Jaeger collector — it never runs a Thrift RPC server that accepts untrusted
incoming messages. The
+vulnerable server-side allocation path is therefore never reached.</p>
+<p>Solr shipped an affected <code>libthrift</code> in the
8.x line — 0.12.0 (8.2.0) and 0.13.0 (8.5.0 – 8.8.1),
+both ≤ 0.13.0 — so the affected range is 8.2.0 – 8.8.1. Solr 9.0.0 upgraded to
<code>libthrift</code> 0.14.1
+(and later 0.15.0), which are past the 0.14.0 fix, so no 9.x or 10.x release
is affected. (The Solr
+8.x line is end of life.)</p></content><category
term="solr/vex"/></entry><entry><title>Bouncy Castle (bcprov): LDAP CertStore
injection, EC/Ed25519 DoS, and RSA/TLS timing side-channel</title><link
href="/cve-2023-33201.html"
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2025-09-07:/cve-2023-33201.html</id><summary
type="html"><p>Four vulnerabilities in th [...]
each in a distinct crypto operation:</p>
<ul>
<li><strong>CVE-2023-33201</strong> — LDAP injection in the
X.509 <code>CertStore</code> (fixed in 1.74); requires using Bouncy
diff --git a/output/security-dependency-cves.html
b/output/security-dependency-cves.html
index 7d8b3831c..4c8f95cb9 100644
--- a/output/security-dependency-cves.html
+++ b/output/security-dependency-cves.html
@@ -686,6 +686,15 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
</tr>
<tr>
<td>
+<a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13949">CVE-2020-13949</a>
</td>
+ <td>8.2.0-8.8.1</td>
+ <td>
+ libthrift-0.13.0.jar </td>
+ <td><span class="cdx-not-affected">not affected</span></td>
+ <td><a href="/vex.html#cve-2020-13949">Apache Thrift: server-side
memory-exhaustion DoS via crafted short messages</a></td>
+ </tr>
+ <tr>
+ <td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924">CVE-2025-48924</a>
</td>
<td>9.0.0-9.9.0</td>
<td>
diff --git a/output/solr.openvex.json b/output/solr.openvex.json
index 74e33ae8d..e5e051e94 100644
--- a/output/solr.openvex.json
+++ b/output/solr.openvex.json
@@ -1496,6 +1496,21 @@
"impact_statement": "CVE-2025-48924 is an uncontrolled-recursion issue
in Apache Commons Lang's\n`ClassUtils.getClass(...)`: a very long,
deeply-nested class name can exhaust the stack and\nthrow `StackOverflowError`.
It affects `commons-lang3` from 3.0 up to (but not including) 3.18.0,\nso
dependency scanners flag the `commons-lang3` JAR bundled in Solr 9.x (which
ships versions\n3.12.0 through 3.15.0 across the 9.0\u20139.9 line).\n\nSolr is
**not affected**. The vulnerable `Clas [...]
"status_notes": "Affected Apache Solr versions: 9.0.0-9.9.0."
},
+ {
+ "vulnerability": {
+ "name": "CVE-2020-13949"
+ },
+ "products": [
+ {
+ "@id": "libthrift-0.13.0.jar"
+ }
+ ],
+ "status": "not_affected",
+ "timestamp": "2025-09-07T00:00:00Z",
+ "justification": "vulnerable_code_not_in_execute_path",
+ "impact_statement": "CVE-2020-13949 is a denial-of-service issue in
Apache Thrift: a malicious RPC **client** can send\nspecially-crafted short
messages that cause a Thrift **server** to allocate a large amount of
memory,\npotentially exhausting it (affects `libthrift` 0.9.3 \u2013 0.13.0,
fixed in 0.14.0). It is reachable only\nby an application that runs a Thrift
server accepting messages from untrusted clients.\n\nSolr is **not affected**.
`libthrift` is bundled only by the opti [...]
+ "status_notes": "Affected Apache Solr versions: 8.2.0-8.8.1."
+ },
{
"vulnerability": {
"name": "CVE-2023-33201"
diff --git a/output/solr.vex.json b/output/solr.vex.json
index 80c3d96fe..550808ba8 100644
--- a/output/solr.vex.json
+++ b/output/solr.vex.json
@@ -7,7 +7,7 @@
"name": "solr",
"version": "SNAPSHOT",
"type": "application",
- "bom-ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "bom-ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
},
"vulnerabilities": [
@@ -23,7 +23,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -39,7 +39,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -55,7 +55,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -71,7 +71,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -87,7 +87,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -103,7 +103,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -119,7 +119,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -135,7 +135,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -151,7 +151,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -167,7 +167,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -183,7 +183,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -199,7 +199,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -215,7 +215,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -231,7 +231,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -247,7 +247,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -263,7 +263,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -279,7 +279,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -295,7 +295,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -311,7 +311,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -327,7 +327,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -343,7 +343,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -359,7 +359,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -375,7 +375,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -391,7 +391,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -407,7 +407,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -423,7 +423,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -439,7 +439,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -455,7 +455,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -471,7 +471,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -487,7 +487,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -503,7 +503,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -519,7 +519,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -535,7 +535,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -551,7 +551,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -567,7 +567,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -583,7 +583,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -599,7 +599,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -615,7 +615,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -631,7 +631,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -647,7 +647,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -663,7 +663,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -679,7 +679,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -695,7 +695,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -711,7 +711,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -727,7 +727,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -743,7 +743,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -759,7 +759,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -775,7 +775,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -791,7 +791,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -807,7 +807,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -823,7 +823,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -839,7 +839,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -855,7 +855,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -871,7 +871,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -887,7 +887,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -903,7 +903,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -919,7 +919,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -935,7 +935,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -951,7 +951,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -970,7 +970,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -986,7 +986,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1002,7 +1002,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1018,7 +1018,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1037,7 +1037,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1053,7 +1053,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1070,7 +1070,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1087,7 +1087,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1104,7 +1104,24 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
+ }
+ ]
+ },
+ {
+ "id": "CVE-2020-13949",
+ "source": {
+ "name": "NVD",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13949"
+ },
+ "analysis": {
+ "state": "not_affected",
+ "justification": "code_not_reachable",
+ "detail": "CVE-2020-13949 is a denial-of-service issue in Apache
Thrift: a malicious RPC **client** can send\nspecially-crafted short messages
that cause a Thrift **server** to allocate a large amount of
memory,\npotentially exhausting it (affects `libthrift` 0.9.3 \u2013 0.13.0,
fixed in 0.14.0). It is reachable only\nby an application that runs a Thrift
server accepting messages from untrusted clients.\n\nSolr is **not affected**.
`libthrift` is bundled only by the optional Jae [...]
+ },
+ "affects": [
+ {
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1121,7 +1138,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1138,7 +1155,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1155,7 +1172,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1172,7 +1189,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1189,7 +1206,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1206,7 +1223,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1223,7 +1240,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1240,7 +1257,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1257,7 +1274,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1274,7 +1291,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1291,7 +1308,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1308,7 +1325,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1325,7 +1342,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1342,7 +1359,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1359,7 +1376,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1376,7 +1393,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1396,7 +1413,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1416,7 +1433,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1436,7 +1453,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1453,7 +1470,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1473,7 +1490,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1490,7 +1507,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1507,7 +1524,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1524,7 +1541,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1541,7 +1558,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1558,7 +1575,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1575,7 +1592,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1592,7 +1609,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1609,7 +1626,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1626,7 +1643,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1643,7 +1660,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1660,7 +1677,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1677,7 +1694,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1694,7 +1711,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1711,7 +1728,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1728,7 +1745,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1745,7 +1762,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1762,7 +1779,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1779,7 +1796,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1796,7 +1813,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1813,7 +1830,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1830,7 +1847,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1847,7 +1864,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1864,7 +1881,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1881,7 +1898,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1898,7 +1915,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1915,7 +1932,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1932,7 +1949,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1949,7 +1966,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1966,7 +1983,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -1983,7 +2000,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2000,7 +2017,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2017,7 +2034,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2034,7 +2051,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2051,7 +2068,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2068,7 +2085,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2085,7 +2102,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2102,7 +2119,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2119,7 +2136,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2136,7 +2153,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2153,7 +2170,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2170,7 +2187,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2187,7 +2204,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2204,7 +2221,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2221,7 +2238,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2238,7 +2255,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2255,7 +2272,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2272,7 +2289,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2289,7 +2306,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2306,7 +2323,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2323,7 +2340,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2340,7 +2357,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2357,7 +2374,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2374,7 +2391,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2391,7 +2408,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2408,7 +2425,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2425,7 +2442,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
},
@@ -2442,7 +2459,7 @@
},
"affects": [
{
- "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
+ "ref": "772b4fa6-18d7-5834-9d26-49313bbb8b4d"
}
]
}
diff --git a/output/vex.html b/output/vex.html
index fe68553e6..31a4bd354 100644
--- a/output/vex.html
+++ b/output/vex.html
@@ -2539,6 +2539,42 @@ module, fixed to 1.78.1 in 9.7; the same not-affected
reasoning applies.)</p>
<li>CVE: <a
href="https://nvd.nist.gov/vuln/detail/CVE-2023-33201">CVE-2023-33201</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2024-29857">CVE-2024-29857</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2024-30171">CVE-2024-30171</a>, <a
href="https://nvd.nist.gov/vuln/detail/CVE-2024-30172">CVE-2024-30172</a></li>
</ul>
</article>
+ <article id="cve-2020-13949" class="post panel radius">
+ <header class="post-header">
+ <h3 class="title"><a
href="https://nvd.nist.gov/vuln/detail/CVE-2020-13949">CVE-2020-13949</a>,
Apache Thrift: server-side memory-exhaustion DoS via crafted short messages</h3>
+ <div class="panel callout">
+ <p class="subheader">
+ <strong>Published:</strong>
+ <time
datetime="2025-09-07T00:00:00+00:00">2025-09-07</time>
+ </p>
+ <p class="subheader">
+ <strong>Status:</strong>
+ <span class="cdx-not-affected">not_affected</span>
+ </p>
+ <p class="subheader"><strong>Affected Solr
versions:</strong> 8.2.0-8.8.1</p>
+ </div>
+ </header>
+
+ <h4>Description</h4>
+ <p>CVE-2020-13949 is a denial-of-service issue in Apache
Thrift: a malicious RPC <strong>client</strong> can send
+specially-crafted short messages that cause a Thrift <strong>server</strong>
to allocate a large amount of memory,
+potentially exhausting it (affects <code>libthrift</code> 0.9.3 – 0.13.0,
fixed in 0.14.0). It is reachable only
+by an application that runs a Thrift server accepting messages from untrusted
clients.</p>
+<p>Solr is <strong>not affected</strong>. <code>libthrift</code> is bundled
only by the optional Jaeger distributed-tracing
+integration, where Solr uses Thrift purely as a <strong>client</strong> to
export spans to an operator-configured
+Jaeger collector — it never runs a Thrift RPC server that accepts untrusted
incoming messages. The
+vulnerable server-side allocation path is therefore never reached.</p>
+<p>Solr shipped an affected <code>libthrift</code> in the 8.x line — 0.12.0
(8.2.0) and 0.13.0 (8.5.0 – 8.8.1),
+both ≤ 0.13.0 — so the affected range is 8.2.0 – 8.8.1. Solr 9.0.0 upgraded to
<code>libthrift</code> 0.14.1
+(and later 0.15.0), which are past the 0.14.0 fix, so no 9.x or 10.x release
is affected. (The Solr
+8.x line is end of life.)</p>
+
+ <h4>References</h4>
+ <ul>
+ <li>JIRA: <a
href="https://issues.apache.org/jira/browse/SOLR-15507">SOLR-15507</a></li>
+ <li>CVE: <a
href="https://nvd.nist.gov/vuln/detail/CVE-2020-13949">CVE-2020-13949</a></li>
+ </ul>
+ </article>
<article id="cve-2025-48924" class="post panel radius">
<header class="post-header">
<h3 class="title"><a
href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924">CVE-2025-48924</a>,
Apache Commons Lang: uncontrolled recursion in ClassUtils.getClass</h3>