Re: Lucene/Solr 8.11.1 release

2021-12-12 Thread Jan Høydahl
There seems to be no open blockers for 8.11.1, so I'll proceed with RC1 soon. Shout out if you want me to wait for a specific important bugfix. Please also review the Release Notes at https://cwiki.apache.org/confluence/display/SOLR/ReleaseNote8_11_1 Jan > 8. des. 2021 kl. 02:48 skrev Timothy

Re: Risks of Log4j 2 with the Prometheus Exporter?

2021-12-12 Thread Uwe Schindler
+1 I was wondering about this, too. It makes mitigation too complex. There is no risk in the exporter script. Just mention this as a single sentence. Possibly also add the sentence u declining the importance and why in my previous message on private list. Am 12. Dezember 2021 22:16:38 UTC schr

Risks of Log4j 2 with the Prometheus Exporter?

2021-12-12 Thread David Smiley
Just a simple question here -- does the Prometheus Exporter present a risk for the Log4j 2 vulnerability? It was added to the news page but instinctively I don't see how an attacker might exploit it. If it's not expected to be a concern, I think we should state so in the news; no reason to raise

[ANNOUNCEMENT] Solr's Docker images were updated to remediate a CVE

2021-12-12 Thread David Smiley
Apache Solr's Docker images were updated some hours ago with a simple remediation to avoid the Log4j 2 vulnerability[1] that many of you are becoming aware of -- Log4j 2 CVE-2021-44228. Just a "docker pull solr:tagVersionYouUse" (e.g. 8.11 or whatever) will update it for you. The remediation in t