[ 
https://issues.apache.org/jira/browse/SOLR-17899?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Eric Pugh resolved SOLR-17899.
------------------------------
    Fix Version/s: 10.1
                   9.11
       Resolution: Fixed

Tika no longer ships in process, and the underlying jars are removed in Tika 3 
used in Solr 10

> CVE-2024-30171, CVE-2024-30172, CVE-2024-29857, CVE-2023-33201 : 
> vulnerabilities in Bouncy Castle provider 1.70 dependency
> --------------------------------------------------------------------------------------------------------------------------
>
>                 Key: SOLR-17899
>                 URL: https://issues.apache.org/jira/browse/SOLR-17899
>             Project: Solr
>          Issue Type: Bug
>    Affects Versions: 9.9.0
>            Reporter: Alexander Veit
>            Assignee: Eric Pugh
>            Priority: Major
>              Labels: pull-request-available, security
>             Fix For: 10.1, 9.11
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> {{org.bouncycastle:bcprov-jdk15on:1.70}} (Dec 2021) which is included in Solr 
> 9.9.0 comes with four CVEs:
>  * [https://nvd.nist.gov/vuln/detail/CVE-2024-30171]
>  * [https://nvd.nist.gov/vuln/detail/CVE-2024-30172]
>  * [https://nvd.nist.gov/vuln/detail/CVE-2024-29857]
>  * [https://nvd.nist.gov/vuln/detail/CVE-2023-33201]
>  Possible solution: Upgrade to the latest 
> {{{}org.bouncycastle:bcprov-jdk18on{}}}.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to