[ https://issues.apache.org/jira/browse/SOLR-13648?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Vijay Telu updated SOLR-13648: ------------------------------ Security: Public (was: Private (Security Issue)) > vulnerable simple-xml-2.7.1.jar > ------------------------------- > > Key: SOLR-13648 > URL: https://issues.apache.org/jira/browse/SOLR-13648 > Project: Solr > Issue Type: Bug > Security Level: Public(Default Security Level. Issues are Public) > Components: contrib - Clustering > Affects Versions: 8.0, 8.1.1 > Reporter: Vijay Telu > Priority: Critical > Labels: security > > simple-xml-2.7.1.jar > *File Path:* > org.apache.solr-7.7.1/contrib/clustering/lib/simple-xml-2.7.1.jar > org.apache.solr-8.1.1/contrib/clustering/lib/simple-xml-2.7.1.jar > *CVE-2017-1000190* > *CVSSv3: 9.1* > SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability > resulting SSRF, information disclosure, DoS and so on. -- This message was sent by Atlassian JIRA (v7.6.14#76016) --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@lucene.apache.org For additional commands, e-mail: dev-h...@lucene.apache.org