This is an automated email from the ASF dual-hosted git repository.

github-actions[bot] pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/solr-site.git


The following commit(s) were added to refs/heads/asf-staging by this push:
     new a7f24c206 Commit build products
a7f24c206 is described below

commit a7f24c206bfe8950df145db0ce3e0cfd9b0cb398
Author: Build Pelican (action) <[email protected]>
AuthorDate: Thu Aug 13 01:55:19 2026 +0000

    Commit build products
---
 output/feeds/solr/vex.atom.xml       |   1 +
 output/security-dependency-cves.html |   2 +-
 output/solr.openvex.json             |  60 +++----
 output/solr.vex.json                 | 326 +++++++++++++++++------------------
 output/vex.html                      |   3 +-
 5 files changed, 197 insertions(+), 195 deletions(-)

diff --git a/output/feeds/solr/vex.atom.xml b/output/feeds/solr/vex.atom.xml
index a9403541e..9c035b832 100644
--- a/output/feeds/solr/vex.atom.xml
+++ b/output/feeds/solr/vex.atom.xml
@@ -1512,6 +1512,7 @@ transitive dependency on 
&lt;code&gt;struts-core&lt;/code&gt;, &lt;code&gt;strut
 ship any Struts jar — the dependency is excluded and only appears as a 
transitive POM listing
 (see SOLR-2849) — so these Struts vulnerabilities are not present in, or 
exploitable through, Solr.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>vorbis-java-tika</title><link 
href="/cve-2016-6809.html" 
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2022-12-14:/cve-2016-6809.html</id><content
 type="html">&lt;p&gt;See https://github.com/Gagravarr/Vo [...]
 &lt;p&gt;Tika as an in-process component was removed in Solr 
9.11.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>org.restlet</title><link 
href="/cve-2017-14868.html" 
rel="alternate"/><published>2022-12-14T00:00:00+00:00</published><updated>2022-12-14T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2022-12-14:/cve-2017-14868.html</id><content
 type="html">&lt;p&gt;Solr should not be exposed outside a firewall where bad 
actors can send [...]
+&lt;p&gt;All 15 are pre-block-list "individual gadget" CVEs, fixed in 
jackson-databind ≤ 2.9.10.7 / ≤ 2.10.5.1 (the latest, CVE-2021-20190, in 
2.10.5.1). Solr's &lt;strong&gt;standalone&lt;/strong&gt; 
&lt;code&gt;jackson-databind&lt;/code&gt; — the 
&lt;code&gt;jackson-databind-*.jar&lt;/code&gt; this statement covers — was 
within that range from 4.7.0 through Solr &lt;strong&gt;8.6.3&lt;/strong&gt;: 
2.9.x up to 8.3.1, then 2.10.0 / 2.10.1 through 8.6.3 (all &amp;lt; 2.10.5.1). 
Solr 8.7.0 [...]
 &lt;p&gt;SOLR-17236 tracks this same class of jackson-databind deserialization 
CVEs for the old 2.x copy shaded inside Hadoop's 
&lt;code&gt;htrace-core4&lt;/code&gt; jar in the 8.x line; the same reasoning 
applies, and &lt;code&gt;htrace-core4&lt;/code&gt; (with its bundled 
jackson-databind) was removed in Solr 9.x.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>hadoop-auth</title><link 
href="/cve-2017-15718.html" 
rel="alternate"/><published>2022-12-14T00:00:00+00:00 [...]
 releases up to and including 2.0.6 (fixed in 2.0.6.1). Solr has bundled JDOM 
(transitively, via
 Apache Tika / Solr Cell) since Solr 3.6.0 — &lt;code&gt;jdom&lt;/code&gt; 1.0, 
then &lt;code&gt;jdom&lt;/code&gt; 2.0 …&lt;/p&gt;</summary><content 
type="html">&lt;p&gt;CVE-2021-33813 is an XML external entity (XXE) issue in 
JDOM's &lt;code&gt;SAXBuilder&lt;/code&gt;, affecting all JDOM
diff --git a/output/security-dependency-cves.html 
b/output/security-dependency-cves.html
index 7db116932..b55f42b9a 100644
--- a/output/security-dependency-cves.html
+++ b/output/security-dependency-cves.html
@@ -930,7 +930,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15095";>CVE-2017-15095</a>, 
<a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17485";>CVE-2017-17485</a>, 
<a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7525";>CVE-2017-7525</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2018-5968";>CVE-2018-5968</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2018-7489";>CVE-2018-7489</a>, <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2019-12086";>CVE-2019-12086</a>, <a 
href="https://nvd.nist.gov/ [...]
-      <td>4.7.0-8.x</td>
+      <td>4.7.0-8.6.3</td>
       <td>
           jackson-databind-*.jar      </td>
       <td><span class="cdx-not-affected">not affected</span></td>
diff --git a/output/solr.openvex.json b/output/solr.openvex.json
index 914b55e6e..b4ae87877 100644
--- a/output/solr.openvex.json
+++ b/output/solr.openvex.json
@@ -377,8 +377,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -391,8 +391,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -405,8 +405,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -419,8 +419,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -433,8 +433,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -447,8 +447,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -461,8 +461,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -475,8 +475,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -489,8 +489,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -503,8 +503,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -517,8 +517,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -531,8 +531,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -545,8 +545,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -559,8 +559,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
@@ -573,8 +573,8 @@
       ],
       "status": "not_affected",
       "timestamp": "2022-12-14T00:00:00Z",
-      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
-      "status_notes": "Affected Apache Solr versions: 4.7.0-8.x."
+      "impact_statement": "These CVEs, and most of the known jackson-databind 
CVEs since 2017, are all related to problematic 'gadgets' that could be 
exploited during deserialization of untrusted data. The Jackson developers 
described 4 conditions that must be met in order for a problematic gadget to be 
exploited. See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions d [...]
+      "status_notes": "Affected Apache Solr versions: 4.7.0-8.6.3."
     },
     {
       "vulnerability": {
diff --git a/output/solr.vex.json b/output/solr.vex.json
index 6a49fbd5a..54be4fe43 100644
--- a/output/solr.vex.json
+++ b/output/solr.vex.json
@@ -7,7 +7,7 @@
       "name": "solr",
       "version": "SNAPSHOT",
       "type": "application",
-      "bom-ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+      "bom-ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
     }
   },
   "vulnerabilities": [
@@ -23,7 +23,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -39,7 +39,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -55,7 +55,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -71,7 +71,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -87,7 +87,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -103,7 +103,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -119,7 +119,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -135,7 +135,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -151,7 +151,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -167,7 +167,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -183,7 +183,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -199,7 +199,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -215,7 +215,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -231,7 +231,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -247,7 +247,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -263,7 +263,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -279,7 +279,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -295,7 +295,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -311,7 +311,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -327,7 +327,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -343,7 +343,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -359,7 +359,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -375,7 +375,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -387,11 +387,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -403,11 +403,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -419,11 +419,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -435,11 +435,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -451,11 +451,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -467,11 +467,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -483,11 +483,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -499,11 +499,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -515,11 +515,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -531,11 +531,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -547,11 +547,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -563,11 +563,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -579,11 +579,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -595,11 +595,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -611,11 +611,11 @@
       },
       "analysis": {
         "state": "not_affected",
-        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+        "detail": "These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -631,7 +631,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -647,7 +647,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -663,7 +663,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -679,7 +679,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -695,7 +695,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -711,7 +711,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -727,7 +727,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -743,7 +743,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -759,7 +759,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -775,7 +775,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -791,7 +791,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -807,7 +807,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -823,7 +823,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -839,7 +839,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -855,7 +855,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -871,7 +871,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -887,7 +887,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -903,7 +903,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -919,7 +919,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -935,7 +935,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -951,7 +951,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -970,7 +970,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -986,7 +986,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1002,7 +1002,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1018,7 +1018,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1037,7 +1037,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1053,7 +1053,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1070,7 +1070,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1087,7 +1087,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1104,7 +1104,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1121,7 +1121,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1138,7 +1138,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1155,7 +1155,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1172,7 +1172,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1189,7 +1189,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1206,7 +1206,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1223,7 +1223,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1240,7 +1240,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1257,7 +1257,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1274,7 +1274,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1291,7 +1291,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1308,7 +1308,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1325,7 +1325,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1342,7 +1342,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1359,7 +1359,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1376,7 +1376,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1393,7 +1393,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1413,7 +1413,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1433,7 +1433,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1453,7 +1453,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1470,7 +1470,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1490,7 +1490,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1507,7 +1507,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1524,7 +1524,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1541,7 +1541,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1558,7 +1558,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1575,7 +1575,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1592,7 +1592,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1609,7 +1609,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1626,7 +1626,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1643,7 +1643,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1660,7 +1660,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1677,7 +1677,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1694,7 +1694,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1711,7 +1711,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1728,7 +1728,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1745,7 +1745,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1762,7 +1762,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1779,7 +1779,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1796,7 +1796,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1813,7 +1813,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1830,7 +1830,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1847,7 +1847,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1864,7 +1864,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1881,7 +1881,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1898,7 +1898,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1915,7 +1915,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1932,7 +1932,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1949,7 +1949,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1966,7 +1966,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -1983,7 +1983,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2000,7 +2000,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2017,7 +2017,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2034,7 +2034,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2051,7 +2051,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2068,7 +2068,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2085,7 +2085,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2102,7 +2102,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2119,7 +2119,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2136,7 +2136,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2153,7 +2153,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2170,7 +2170,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2187,7 +2187,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2204,7 +2204,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2221,7 +2221,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2238,7 +2238,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2255,7 +2255,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2272,7 +2272,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2289,7 +2289,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2306,7 +2306,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2323,7 +2323,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2340,7 +2340,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2357,7 +2357,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2374,7 +2374,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2391,7 +2391,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2408,7 +2408,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2425,7 +2425,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2442,7 +2442,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     },
@@ -2459,7 +2459,7 @@
       },
       "affects": [
         {
-          "ref": "21da88c8-25b3-584a-886e-d79053178eaa"
+          "ref": "b9b908f7-4940-575d-8676-3e5ab0d7d761"
         }
       ]
     }
diff --git a/output/vex.html b/output/vex.html
index da57356df..f1c47d267 100644
--- a/output/vex.html
+++ b/output/vex.html
@@ -3231,12 +3231,13 @@ therefore 3.6.0 – 8.8.1.</p>
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 4.7.0-8.x</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 4.7.0-8.6.3</p>
                     </div>
                 </header>
 
                 <h4>Description</h4>
                 <p>These CVEs, and most of the known jackson-databind CVEs 
since 2017, are all related to problematic 'gadgets' that could be exploited 
during deserialization of untrusted data. The Jackson developers described 4 
conditions that must be met in order for a problematic gadget to be exploited. 
See 
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062.
 Solr's use of jackson-databind does not meet 1 of the 4 conditions described 
[...]
+<p>All 15 are pre-block-list "individual gadget" CVEs, fixed in 
jackson-databind ≤ 2.9.10.7 / ≤ 2.10.5.1 (the latest, CVE-2021-20190, in 
2.10.5.1). Solr's <strong>standalone</strong> <code>jackson-databind</code> — 
the <code>jackson-databind-*.jar</code> this statement covers — was within that 
range from 4.7.0 through Solr <strong>8.6.3</strong>: 2.9.x up to 8.3.1, then 
2.10.0 / 2.10.1 through 8.6.3 (all &lt; 2.10.5.1). Solr 8.7.0 moved to 
jackson-databind 2.11.2 — past the fix — and 9.x [...]
 <p>SOLR-17236 tracks this same class of jackson-databind deserialization CVEs 
for the old 2.x copy shaded inside Hadoop's <code>htrace-core4</code> jar in 
the 8.x line; the same reasoning applies, and <code>htrace-core4</code> (with 
its bundled jackson-databind) was removed in Solr 9.x.</p>
 
                 <h4>References</h4>

Reply via email to