Ivan Viaznikov created SOLR-15911:
-------------------------------------
Summary: Protobuf 3.16.1 compatibility
Key: SOLR-15911
URL: https://issues.apache.org/jira/browse/SOLR-15911
Project: Solr
Issue Type: Test
Security Level: Public (Default Security Level. Issues are Public)
Reporter: Ivan Viaznikov
A vulnerability (https://nvd.nist.gov/vuln/detail/CVE-2021-22569) was
discovered that affects protobuf-java. The version `3.11.0` of this library
comes as a dependency with `org.apache.solr:solr-clustering` and
`org.apache.solr:solr-analysis-extras`. However, the vulnerability is only
fixed in versions `3.19.2`, `3.18.2` and `3.16.1`.
Therefore, requesting you to clarify if any of the fixed versions of
protobuf-java are compatible with `org.apache.solr:solr-clustering` and
`org.apache.solr:solr-analysis-extras`
--
This message was sent by Atlassian Jira
(v8.20.1#820001)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]