Details
-
Bug
-
Status: Resolved
-
Major
-
Resolution: Won't Fix
-
7.6, 8.0
-
None
-
None
Description
The Solr package contains dom4j-1.6.1 in the server webapp component in server/solr-webapp/webapp/WEB-INF/lib/dom4j-1.6.1.jar
Please can you upgrade dom4j-1.6.1 due to open security vulnerability to 2.1.1+.
If you need the CVE number, let me know.
Attachments
Issue Links
- duplicates
-
SOLR-13113 CVE-2018-1000632 Threat Level 7 Against Solr v7.6. dom4j : dom4j : 1.6.1. dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute ...
- Resolved
- is related to
-
SOLR-13342 Remove dom4j from Solr
- Closed