[ 
https://issues.apache.org/jira/browse/SOLR-7106?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14321543#comment-14321543
 ] 

Yonik Seeley commented on SOLR-7106:
------------------------------------

Can you explain in what sense it's a security vulnerability?  I'm not saying 
that it isn't... but understanding the exact issues we're worried about would 
be helpful.

For example, allowing read/write access to the entire index by default could 
also be considered a security vulnerability, but we're OK with that.

> Disable dynamic loading by default
> ----------------------------------
>
>                 Key: SOLR-7106
>                 URL: https://issues.apache.org/jira/browse/SOLR-7106
>             Project: Solr
>          Issue Type: Task
>            Reporter: Noble Paul
>            Assignee: Noble Paul
>            Priority: Blocker
>             Fix For: 5.0
>
>         Attachments: SOLR-7106.patch, SOLR-7106.patch
>
>
> Dynamic loading of jars is enabled by default SOLR-6801. It is a security 
> vulnerability and we should set it to be disabled by default



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to