[
https://issues.apache.org/jira/browse/SOLR-14844?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17215820#comment-17215820
]
Samuel García Martínez commented on SOLR-14844:
-----------------------------------------------
Sure! I'll submit the patches on Sunday.
I wasn't aware of the process regarding the JIRA ticket assignee. "The best
part of sharing success with someone is that you can share the blame also" - Me
🤣
I'll let you know if I run into any issue. Thanks for the tips!
> Upgrade Jetty to 9.4.32.v20200930
> ---------------------------------
>
> Key: SOLR-14844
> URL: https://issues.apache.org/jira/browse/SOLR-14844
> Project: Solr
> Issue Type: Improvement
> Affects Versions: 8.6
> Reporter: Cassandra Targett
> Assignee: Erick Erickson
> Priority: Major
> Attachments: SOLR-14844-master.patch, SOLR-14884-8x.patch
>
>
> A CVE was found in Jetty 9.4.27-9.4.29 that has some security scanning tools
> raising red flags
> ([https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17638]).
> Here's the Jetty issue:
> [https://bugs.eclipse.org/bugs/show_bug.cgi?id=564984]. It's fixed in
> 9.4.30+, so we should upgrade to that for 8.7
> -It has a simple mitigation (raise Jetty's responseHeaderSize to higher than
> requestHeaderSize), but I don't know how Solr uses Jetty well enough to a)
> know if this problem is even exploitable in Solr, or b) if the workaround
> suggested is even possible in Solr.-
> In normal Solr installs, w/o jetty optimizations, this issue is largely
> mitigated in 8.6.3: see SOLR-14896 (and linked bug fixes) for details.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]