[ 
https://issues.apache.org/jira/browse/SOLR-16141?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17517535#comment-17517535
 ] 

Kevin Risden commented on SOLR-16141:
-------------------------------------

In Apache Solr 9.0 - Solr only has a dependency on Tika (which pulls in POI). 
https://github.com/apache/solr/blob/main/versions.lock#L187

Tika looks like it would need to be upgraded from 1.28.1 to a 2.x to get the 
latest POI version.

> Update Apache poi to the version 5.2.1
> --------------------------------------
>
>                 Key: SOLR-16141
>                 URL: https://issues.apache.org/jira/browse/SOLR-16141
>             Project: Solr
>          Issue Type: Wish
>      Security Level: Public(Default Security Level. Issues are Public) 
>            Reporter: Ivan Viaznikov
>            Priority: Major
>
> org.apache.solr:solr-cell module uses Apache POI. Apache POI version 5.2.1 
> includes several bug fixes, including a resolution for CVE-2022-26336, which 
> impacts poi-scratchpad.
> Therefore requesting you to update the version of Apache POI to 5.2.1



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@solr.apache.org
For additional commands, e-mail: issues-h...@solr.apache.org

Reply via email to