RE: CVEs (vulnerabilities) that apply to Solr 8.4.1

2020-03-20 Thread Ahlberg, Christopher C.
apply to Solr 8.4.1 ATTENTION! This email originated outside of DTCC; exercise caution. https://lucene.apache.org/solr/security.html<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Flucene.apache.org%2Fsolr%2Fsecurity.html&data=02%7C01%7Ccahlberg%40d

Re: CVEs (vulnerabilities) that apply to Solr 8.4.1

2020-03-20 Thread Kevin Risden
https://lucene.apache.org/solr/security.html The security page on the Solr website has details about how to report security items. It also has a link to the wiki page with details about some of these that are false positives. Each version of Solr has dependency updates and addresses different dep

CVEs (vulnerabilities) that apply to Solr 8.4.1

2020-03-20 Thread Ahlberg, Christopher C.
Our TRM team (Technology Risk Management) has provided us with the attached vulnerabilities analysis for Solr 8.4.1, (security issues extracted below.) Has anyone out there in the Solr community done anything to document workarounds or mitigations for any of these identified vulnerabilities in S