This is an automated email from the ASF dual-hosted git repository.
github-actions[bot] pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/solr-site.git
The following commit(s) were added to refs/heads/asf-staging by this push:
new 63762d45a Commit build products
63762d45a is described below
commit 63762d45a8d8991f208e3268ea9309bdc13c93ff
Author: Build Pelican (action) <[email protected]>
AuthorDate: Thu Aug 13 01:47:14 2026 +0000
Commit build products
---
output/feeds/solr/vex.atom.xml | 3 +-
output/solr.openvex.json | 30 ++--
output/solr.vex.json | 326 ++++++++++++++++++++---------------------
output/vex.html | 1 +
4 files changed, 181 insertions(+), 179 deletions(-)
diff --git a/output/feeds/solr/vex.atom.xml b/output/feeds/solr/vex.atom.xml
index fff19317d..a9403541e 100644
--- a/output/feeds/solr/vex.atom.xml
+++ b/output/feeds/solr/vex.atom.xml
@@ -1511,7 +1511,8 @@ ship any Struts jar — the dependency is excluded and only
appears as a transit
transitive dependency on <code>struts-core</code>,
<code>struts-taglib</code> and
<code>struts-tiles</code> 1.3.8. Solr does not
ship any Struts jar — the dependency is excluded and only appears as a
transitive POM listing
(see SOLR-2849) — so these Struts vulnerabilities are not present in, or
exploitable through, Solr.</p></content><category
term="solr/vex"/></entry><entry><title>vorbis-java-tika</title><link
href="/cve-2016-6809.html"
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2022-12-14:/cve-2016-6809.html</id><content
type="html"><p>See https://github.com/Gagravarr/Vo [...]
-<p>Tika as an in-process component was removed in Solr
9.11.</p></content><category
term="solr/vex"/></entry><entry><title>org.restlet</title><link
href="/cve-2017-14868.html"
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2022-12-14:/cve-2017-14868.html</id><content
type="html"><p>Solr should not be exposed outside a firewall where bad
actors can send [...]
+<p>Tika as an in-process component was removed in Solr
9.11.</p></content><category
term="solr/vex"/></entry><entry><title>org.restlet</title><link
href="/cve-2017-14868.html"
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
Developers</name></author><id>tag:None,2022-12-14:/cve-2017-14868.html</id><content
type="html"><p>Solr should not be exposed outside a firewall where bad
actors can send [...]
+<p>SOLR-17236 tracks this same class of jackson-databind deserialization
CVEs for the old 2.x copy shaded inside Hadoop's
<code>htrace-core4</code> jar in the 8.x line; the same reasoning
applies, and <code>htrace-core4</code> (with its bundled
jackson-databind) was removed in Solr 9.x.</p></content><category
term="solr/vex"/></entry><entry><title>hadoop-auth</title><link
href="/cve-2017-15718.html"
rel="alternate"/><published>2022-12-14T00:00:00+00:00 [...]
releases up to and including 2.0.6 (fixed in 2.0.6.1). Solr has bundled JDOM
(transitively, via
Apache Tika / Solr Cell) since Solr 3.6.0 — <code>jdom</code> 1.0,
then <code>jdom</code> 2.0 …</p></summary><content
type="html"><p>CVE-2021-33813 is an XML external entity (XXE) issue in
JDOM's <code>SAXBuilder</code>, affecting all JDOM
releases up to and including 2.0.6 (fixed in 2.0.6.1). Solr has bundled JDOM
(transitively, via
diff --git a/output/solr.openvex.json b/output/solr.openvex.json
index 65a084d27..914b55e6e 100644
--- a/output/solr.openvex.json
+++ b/output/solr.openvex.json
@@ -377,7 +377,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -391,7 +391,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -405,7 +405,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -419,7 +419,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -433,7 +433,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -447,7 +447,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -461,7 +461,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -475,7 +475,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -489,7 +489,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -503,7 +503,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -517,7 +517,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -531,7 +531,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -545,7 +545,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -559,7 +559,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
@@ -573,7 +573,7 @@
],
"status": "not_affected",
"timestamp": "2022-12-14T00:00:00Z",
- "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+ "impact_statement": "These CVEs, and most of the known jackson-databind
CVEs since 2017, are all related to problematic 'gadgets' that could be
exploited during deserialization of untrusted data. The Jackson developers
described 4 conditions that must be met in order for a problematic gadget to be
exploited. See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
"status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
},
{
diff --git a/output/solr.vex.json b/output/solr.vex.json
index 804a5da6d..6a49fbd5a 100644
--- a/output/solr.vex.json
+++ b/output/solr.vex.json
@@ -7,7 +7,7 @@
"name": "solr",
"version": "SNAPSHOT",
"type": "application",
- "bom-ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "bom-ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
},
"vulnerabilities": [
@@ -23,7 +23,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -39,7 +39,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -55,7 +55,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -71,7 +71,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -87,7 +87,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -103,7 +103,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -119,7 +119,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -135,7 +135,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -151,7 +151,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -167,7 +167,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -183,7 +183,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -199,7 +199,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -215,7 +215,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -231,7 +231,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -247,7 +247,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -263,7 +263,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -279,7 +279,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -295,7 +295,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -311,7 +311,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -327,7 +327,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -343,7 +343,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -359,7 +359,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -375,7 +375,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -387,11 +387,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -403,11 +403,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -419,11 +419,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -435,11 +435,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -451,11 +451,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -467,11 +467,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -483,11 +483,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -499,11 +499,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -515,11 +515,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -531,11 +531,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -547,11 +547,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -563,11 +563,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -579,11 +579,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -595,11 +595,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -611,11 +611,11 @@
},
"analysis": {
"state": "not_affected",
- "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+ "detail": "These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -631,7 +631,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -647,7 +647,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -663,7 +663,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -679,7 +679,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -695,7 +695,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -711,7 +711,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -727,7 +727,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -743,7 +743,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -759,7 +759,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -775,7 +775,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -791,7 +791,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -807,7 +807,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -823,7 +823,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -839,7 +839,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -855,7 +855,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -871,7 +871,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -887,7 +887,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -903,7 +903,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -919,7 +919,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -935,7 +935,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -951,7 +951,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -970,7 +970,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -986,7 +986,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1002,7 +1002,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1018,7 +1018,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1037,7 +1037,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1053,7 +1053,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1070,7 +1070,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1087,7 +1087,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1104,7 +1104,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1121,7 +1121,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1138,7 +1138,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1155,7 +1155,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1172,7 +1172,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1189,7 +1189,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1206,7 +1206,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1223,7 +1223,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1240,7 +1240,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1257,7 +1257,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1274,7 +1274,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1291,7 +1291,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1308,7 +1308,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1325,7 +1325,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1342,7 +1342,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1359,7 +1359,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1376,7 +1376,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1393,7 +1393,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1413,7 +1413,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1433,7 +1433,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1453,7 +1453,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1470,7 +1470,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1490,7 +1490,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1507,7 +1507,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1524,7 +1524,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1541,7 +1541,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1558,7 +1558,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1575,7 +1575,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1592,7 +1592,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1609,7 +1609,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1626,7 +1626,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1643,7 +1643,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1660,7 +1660,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1677,7 +1677,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1694,7 +1694,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1711,7 +1711,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1728,7 +1728,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1745,7 +1745,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1762,7 +1762,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1779,7 +1779,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1796,7 +1796,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1813,7 +1813,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1830,7 +1830,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1847,7 +1847,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1864,7 +1864,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1881,7 +1881,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1898,7 +1898,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1915,7 +1915,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1932,7 +1932,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1949,7 +1949,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1966,7 +1966,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -1983,7 +1983,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2000,7 +2000,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2017,7 +2017,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2034,7 +2034,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2051,7 +2051,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2068,7 +2068,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2085,7 +2085,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2102,7 +2102,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2119,7 +2119,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2136,7 +2136,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2153,7 +2153,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2170,7 +2170,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2187,7 +2187,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2204,7 +2204,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2221,7 +2221,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2238,7 +2238,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2255,7 +2255,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2272,7 +2272,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2289,7 +2289,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2306,7 +2306,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2323,7 +2323,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2340,7 +2340,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2357,7 +2357,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2374,7 +2374,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2391,7 +2391,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2408,7 +2408,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2425,7 +2425,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2442,7 +2442,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
},
@@ -2459,7 +2459,7 @@
},
"affects": [
{
- "ref": "aea743ab-4bda-5ae9-9113-6c9f5fed126d"
+ "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
}
]
}
diff --git a/output/vex.html b/output/vex.html
index 43237d2d4..da57356df 100644
--- a/output/vex.html
+++ b/output/vex.html
@@ -3237,6 +3237,7 @@ therefore 3.6.0 – 8.8.1.</p>
<h4>Description</h4>
<p>These CVEs, and most of the known jackson-databind CVEs
since 2017, are all related to problematic 'gadgets' that could be exploited
during deserialization of untrusted data. The Jackson developers described 4
conditions that must be met in order for a problematic gadget to be exploited.
See
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
Solr's use of jackson-databind does not meet 1 of the 4 conditions described
[...]
+<p>SOLR-17236 tracks this same class of jackson-databind deserialization CVEs
for the old 2.x copy shaded inside Hadoop's <code>htrace-core4</code> jar in
the 8.x line; the same reasoning applies, and <code>htrace-core4</code> (with
its bundled jackson-databind) was removed in Solr 9.x.</p>
<h4>References</h4>
<ul>