Re: CVE-2022-47501: Apache OFBiz: Arbitrary file reading vulnerability

2023-04-11 Thread Jacques Le Roux
Hi Douglas, Your message has been moderated, else it would not have reached this Mailing List. Please subscribe to the user ML for such questions and then use your email client. See why here http://ofbiz.apache.org/mailing-lists.html. You will get a better support, people can answer you on th

RE: CVE-2022-47501: Apache OFBiz: Arbitrary file reading vulnerability

2023-04-11 Thread Douglas Melo
Hello Jacques!! I have a question, is it necessary to update the entire project or just the Solr plugin? On 2023/04/10 09:21:12 Jacques Le Roux wrote: > Severity: important > > Description: > > Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz.This issue affects

CVE-2022-47501: Apache OFBiz: Arbitrary file reading vulnerability

2023-04-10 Thread Jacques Le Roux
Severity: important Description: Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz.This issue affects Apache OFBiz: before 18.12.07. Required Configurations: Using the Solr plugin Solution: Upgrade to release 18.12.07 Credit: Skay (finder) References: https