ctargett commented on a change in pull request #47: URL: https://github.com/apache/solr-site/pull/47#discussion_r766874626
########## File path: content/solr/security/2021-12-12-cve-2021-44228.md ########## @@ -14,8 +14,10 @@ Apache Solr releases prior to 8.11.1 were using a bundled version of the Apache Apache Solr releases prior to 7.0 (i.e. all Solr 5 and Solr 6 releases) use log4j 1.2.17 which may be vulnerable for installations using non-default logging configurations. To determine you if you are vulnerable please consult the Log4J security page. +The Prometheus Exporter Contrib is similarly separately affected. + **Mitigation:** -Any of the following are enough to prevent this vulnerability: +Any of the following are enough to prevent this vulnerability for Solr servers: * Upgrade to `Solr 8.11.1` or greater (when available), which will include an updated version of the log4j2 dependancy. Review comment: typo: "dependency" -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@solr.apache.org For queries about this service, please contact Infrastructure at: us...@infra.apache.org --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@solr.apache.org For additional commands, e-mail: issues-h...@solr.apache.org