[ 
https://issues.apache.org/jira/browse/SOLR-17905?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Alexander Veit updated SOLR-17905:
----------------------------------
    Description: 
org.apache.kafka:kafka-clients:3.9.0 (Nov 2024) which is included in Solr 9.9.0 
comes with CVE-2025-27817 (Score 7.5).

[https://nvd.nist.gov/vuln/detail/CVE-2025-27817]

Possible solution: Update to org.apache.kafka:kafka-clients:3.9.1

  was:
org.apache.kafka:kafka-clients:3.9.0 (Nov 2024) which is included in Solr 9.9.0 
comes with CVE-2025-27817 (Score 7.5).

https://nvd.nist.gov/vuln/detail/CVE-2025-27817



> CVE-2025-27817: vulnerability in kafka-clients 3.9.0 dependency
> ---------------------------------------------------------------
>
>                 Key: SOLR-17905
>                 URL: https://issues.apache.org/jira/browse/SOLR-17905
>             Project: Solr
>          Issue Type: Bug
>    Affects Versions: 9.9.0
>            Reporter: Alexander Veit
>            Priority: Major
>              Labels: security
>
> org.apache.kafka:kafka-clients:3.9.0 (Nov 2024) which is included in Solr 
> 9.9.0 comes with CVE-2025-27817 (Score 7.5).
> [https://nvd.nist.gov/vuln/detail/CVE-2025-27817]
> Possible solution: Update to org.apache.kafka:kafka-clients:3.9.1



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@solr.apache.org
For additional commands, e-mail: issues-h...@solr.apache.org

Reply via email to