[
https://issues.apache.org/jira/browse/SOLR-17825?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18103703#comment-18103703
]
Eric Pugh commented on SOLR-17825:
----------------------------------
I have written a VEX (vulnerablity exploitation file) file that covers this CVE
and highlights that it is NOT actually exploitable in Solr. This is my
perspective, and I'd love any other opinons. Please consult
[https://github.com/apache/solr-site/blob/main/content/solr/vex/2026-07-18-cve-2025-48734.md.]
This information is published publically to
https://solr.apache.org/security-dependency-cves.html.
Based on that VEX file, I will probably resolve this as somethign we won't do
as it's not actually a problem for Solr.
> Upgrade commons-beanutils jar to 1.11.0+ to fix CVE-2025-48734
> ---------------------------------------------------------------
>
> Key: SOLR-17825
> URL: https://issues.apache.org/jira/browse/SOLR-17825
> Project: Solr
> Issue Type: Improvement
> Affects Versions: 9.8.1
> Reporter: Dhoka Pramod
> Priority: Critical
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]