[ 
https://issues.apache.org/jira/browse/SOLR-17833?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18103678#comment-18103678
 ] 

Eric Pugh commented on SOLR-17833:
----------------------------------

I have investigated this as part of looking at other dependency CVE's and we 
are lucky that we don't actually use protobuf.   

Here is the VEX file: 
https://github.com/apache/solr-site/pull/211/changes/2918942e9adf0b05cdf366b1757b7f09147aac9a

> Assess expoitability of CVE-2024-7254 in dependency `protobuf-java`
> -------------------------------------------------------------------
>
>                 Key: SOLR-17833
>                 URL: https://issues.apache.org/jira/browse/SOLR-17833
>             Project: Solr
>          Issue Type: Task
>            Reporter: Piotr Karwasz
>            Assignee: Eric Pugh
>            Priority: Major
>              Labels: security
>
> h2. Vulnerability Assessment Request
> Please assess the exploitability of the following vulnerability in Apache 
> Solr:
> * *Dependency*: `protobuf-java`
> * *CVE ID*: `CVE-2024-7254`
> * *GHSA ID*: `GHSA-735f-pc8j-v9w8`
> * *Severity*: `high`
> protobuf-java has potential Denial of Service issue
> h3. Context
> This issue was automatically created to track and assess the impact of the 
> reported vulnerability on Apache Solr.
> Please provide your analysis and recommended actions.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to