[ https://issues.apache.org/jira/browse/SOLR-17905?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Alexander Veit updated SOLR-17905: ---------------------------------- Description: org.apache.kafka:kafka-clients:3.9.0 (Nov 2024) which is included in Solr 9.9.0 comes with CVE-2025-27817 (Score 7.5). [https://nvd.nist.gov/vuln/detail/CVE-2025-27817] Possible solution: Update to org.apache.kafka:kafka-clients:3.9.1 was: org.apache.kafka:kafka-clients:3.9.0 (Nov 2024) which is included in Solr 9.9.0 comes with CVE-2025-27817 (Score 7.5). https://nvd.nist.gov/vuln/detail/CVE-2025-27817 > CVE-2025-27817: vulnerability in kafka-clients 3.9.0 dependency > --------------------------------------------------------------- > > Key: SOLR-17905 > URL: https://issues.apache.org/jira/browse/SOLR-17905 > Project: Solr > Issue Type: Bug > Affects Versions: 9.9.0 > Reporter: Alexander Veit > Priority: Major > Labels: security > > org.apache.kafka:kafka-clients:3.9.0 (Nov 2024) which is included in Solr > 9.9.0 comes with CVE-2025-27817 (Score 7.5). > [https://nvd.nist.gov/vuln/detail/CVE-2025-27817] > Possible solution: Update to org.apache.kafka:kafka-clients:3.9.1 -- This message was sent by Atlassian Jira (v8.20.10#820010) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@solr.apache.org For additional commands, e-mail: issues-h...@solr.apache.org