Details
-
Improvement
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
None
-
None
Description
Protobuf is used in several of Solr's modules (but not its core). Lets bump the patch level of the version to mitigate recent CVEs found in 3.21.4:
https://nvd.nist.gov/vuln/detail/CVE-2022-3171
https://nvd.nist.gov/vuln/detail/CVE-2022-3509
https://nvd.nist.gov/vuln/detail/CVE-2022-3510
(disclaimer: I haven't investigated these for Solr's susceptibility)
Attachments
Issue Links
- is related to
-
SOLR-16627 Upgrade google-cloud-bom to 0.184.0, re2j to 1.6, and grpc to 1.51.0
- Closed
- links to