[ 
https://issues.apache.org/jira/browse/SOLR-10702?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18103874#comment-18103874
 ] 

Eric Pugh commented on SOLR-10702:
----------------------------------

this has been done...   i am going to create a VEX file though that covers 
**CVE-2022-40152** which was impacting one of the Woodstox versions that Solr 
had, though long since fixed.

> Woodstox API 
> -------------
>
>                 Key: SOLR-10702
>                 URL: https://issues.apache.org/jira/browse/SOLR-10702
>             Project: Solr
>          Issue Type: Bug
>          Components: Build
>    Affects Versions: 5.5.1, 6.5.1
>            Reporter: Rong Chen
>            Priority: Major
>
> similar situation to SOLR-5064, woodstox api has artifact id change from 
> woodstox-core-asl to woodstox-core and upgrade version for woodstox-core-asl 
> 4.4.1 becomes woodstox-core 5.x.
> according to 
> https://issues.apache.org/jira/browse/SOLR-5064?focusedCommentId=15535974&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#comment-15535974
> would you please confirm if woodstox-core-asl can be safely excluded from 
> dependency of solr*?
> if not, what is the plan to upgrade solr dependency from woodstox-core-asl to 
> woodstox-core?
> Thanks.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to