[ 
https://issues.apache.org/jira/browse/SOLR-17825?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18103703#comment-18103703
 ] 

Eric Pugh commented on SOLR-17825:
----------------------------------

I have written a VEX (vulnerablity exploitation file) file that covers this CVE 
and highlights that it is NOT actually exploitable in Solr.  This is my 
perspective, and I'd love any other opinons.  Please consult 
[https://github.com/apache/solr-site/blob/main/content/solr/vex/2026-07-18-cve-2025-48734.md.]
   

This information is published publically to 
https://solr.apache.org/security-dependency-cves.html.

Based on that VEX file, I will probably resolve this as somethign we won't do 
as it's not actually a problem for Solr.   

 

> Upgrade commons-beanutils jar to 1.11.0+ to fix CVE-2025-48734 
> ---------------------------------------------------------------
>
>                 Key: SOLR-17825
>                 URL: https://issues.apache.org/jira/browse/SOLR-17825
>             Project: Solr
>          Issue Type: Improvement
>    Affects Versions: 9.8.1
>            Reporter: Dhoka Pramod
>            Priority: Critical
>




--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to