Details
Description
We can't move to Solr 7 without fixing this issue flagged by Sonatype scan Of Solr - 7.6.0 Build,
Using Scanner 1.56.0-01
Threat Level 8 Against Solr v7.6. com.fasterxml.jackson.core : jackson-databind : 2.9.6
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14718
Attachments
Attachments
Issue Links
- is duplicated by
-
SOLR-13385 Upgrade dependency jackson-databind in solr package contrib/prometheus-exporter/lib
- Closed
- links to