Uploaded image for project: 'Solr'
  1. Solr
  2. SOLR-16568

Update woodstox-core to 6.4.0 to mitigate CVE-2022-40152

    XMLWordPrintableJSON

Details

    • Task
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • 9.1
    • main (10.0), 9.1.1
    • None

    Description

      This was brought up on the mailing list here: https://lists.apache.org/thread/psc4r75o933y22jos4xk5rcwhof48sdw

      The automatically created CVEs against xstream are misleading and read the thread above to try to find out more. Its not clear which CVEs if any are actually valid.

      The only one that looks still valid against woodstox-core is CVE-2022-40152 (https://github.com/advisories/GHSA-3f7h-mf4q-vrm4) and fixed in https://github.com/FasterXML/woodstox/issues/160. It is LOW severity only.


      Our container scan detects woodstox 6.2.8 

      /opt/bitnami/solr/server/solr-webapp/webapp/WEB-INF/lib/woodstox-core-6.2.8.jar

      Attachments

        Issue Links

          Activity

            People

              krisden Kevin Risden
              bkidwell Bill Kidwell
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 40m
                  40m