[ 
https://issues.apache.org/jira/browse/SOLR-13901?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Munendra S N resolved SOLR-13901.
---------------------------------
    Resolution: Duplicate

Jackson is upgraded to latest versions in SOLR-13818 and SOLR-14054. Marking 
this as duplicate of SOLR-13818

> Update jackson-databind to 2.10.0.pr1 for security vulnerabilities
> ------------------------------------------------------------------
>
>                 Key: SOLR-13901
>                 URL: https://issues.apache.org/jira/browse/SOLR-13901
>             Project: Solr
>          Issue Type: Task
>      Security Level: Public(Default Security Level. Issues are Public) 
>          Components: Build
>    Affects Versions: 8.3
>            Reporter: Charles Dumont
>            Priority: Major
>
> This is needed to resolve the following security vulnerabilities: 
> [CVE-2019-14540|[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540]],
>  
> [CVE-2019-16335|[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335]],
>  
> [CVE-2019-16942|[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942]],
>  
> [CVE-2019-16943|[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943]],
>  
> [CVE-2019-17267|[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17267]]
>  and 
> [CVE-2019-17531|[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531]].
> If solr is not impacted by these vulnerabilities then go ahead and 
> de-escalate this issue.  Thanks.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org
For additional commands, e-mail: issues-h...@lucene.apache.org

Reply via email to