Reg CVE 2021-44832

2023-09-05 Thread ramkrishna vasudevan
Hi All, We are internally using Solr 7.5. As part of the zero day log4j vulnerability we already moved the log4j to 2.17.0 version in the solr component. Now the tools that we run internally flags CVE-2021-44832 . But the Solr security page https:/

Re: SOLR-16194 - fix/backport possibly missed on 9.x branch

2023-09-05 Thread Gus Heck
I'll take a look tonight. (commented on issue too) On Tue, Sep 5, 2023 at 8:46 AM Alex Deparvu wrote: > Thank you Jason for confirming. > Unless someone has objections, I will backport this to 9.x in the following > days. > > alex > > > On Mon, Aug 28, 2023 at 1:17 PM Jason Gerlowski > wrote: >

Re: SOLR-16194 - fix/backport possibly missed on 9.x branch

2023-09-05 Thread Alex Deparvu
Thank you Jason for confirming. Unless someone has objections, I will backport this to 9.x in the following days. alex On Mon, Aug 28, 2023 at 1:17 PM Jason Gerlowski wrote: > I wonder whether this wasn't a casualty of the confusion around our > 9.0.0 release. Gus' other commits were in May 2