[ https://issues.apache.org/jira/browse/SOLR-13901?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Munendra S N resolved SOLR-13901. --------------------------------- Resolution: Duplicate Jackson is upgraded to latest versions in SOLR-13818 and SOLR-14054. Marking this as duplicate of SOLR-13818 > Update jackson-databind to 2.10.0.pr1 for security vulnerabilities > ------------------------------------------------------------------ > > Key: SOLR-13901 > URL: https://issues.apache.org/jira/browse/SOLR-13901 > Project: Solr > Issue Type: Task > Security Level: Public(Default Security Level. Issues are Public) > Components: Build > Affects Versions: 8.3 > Reporter: Charles Dumont > Priority: Major > > This is needed to resolve the following security vulnerabilities: > [CVE-2019-14540|[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540]], > > [CVE-2019-16335|[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335]], > > [CVE-2019-16942|[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942]], > > [CVE-2019-16943|[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943]], > > [CVE-2019-17267|[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17267]] > and > [CVE-2019-17531|[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531]]. > If solr is not impacted by these vulnerabilities then go ahead and > de-escalate this issue. Thanks. -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org For additional commands, e-mail: issues-h...@lucene.apache.org