[
https://issues.apache.org/jira/browse/SOLR-17755?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18103683#comment-18103683
]
Eric Pugh commented on SOLR-17755:
----------------------------------
I want to share a link to the current counts in this google doc that I also
shared with the dev mailing list:
[https://docs.google.com/document/d/1fbYFhve8eYYkgzYLiHcHIqsPFX4zvJTApC_4wm-uQVo/edit?tab=t.0#heading=h.xtw3d2wpeib4]
Both 9.11 and 10.1 are head and shoulders better than the previous ones. Plus
the new [https://solr.apache.org/security-dependency-cves.html] page that
provides VEX files that you can feed to docker scount to help you only identify
CVEs that are marked ad exploitable, helps cut down on the numbers of false
positives for those dependnecies that havne't been updated.
Based on both of those criteria, I propose that this ticket can be closed with
a fix version of 9.11 and 10.1?
> Official Docker Images with a horrible number of security vulnerabilities
> -------------------------------------------------------------------------
>
> Key: SOLR-17755
> URL: https://issues.apache.org/jira/browse/SOLR-17755
> Project: Solr
> Issue Type: Bug
> Components: Docker
> Affects Versions: 9.8.1
> Reporter: Alexander Veit
> Assignee: Eric Pugh
> Priority: Major
> Fix For: 10.0
>
> Attachments: Skjermbilde 2025-09-09 kl. 10.41.39.png,
> image-2025-05-07-19-43-18-313.png
>
>
> The official Solr container image adds 73 security vulnerabilities, four of
> them with critical, and 37 of them with high severity, to the base image.
> These vulnerabilities show up not only on DockerHub but also in corporate
> security scans. According to Docker Scout these vulnerabilities could be
> fixed, so they probably should be fixed.
> !image-2025-05-07-19-43-18-313.png!
> https://hub.docker.com/layers/library/solr/9.8.1/images/sha256-2b79aecf860291dc257460e934e275af9bb79fda1991a2c6072535d18a63f07a
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]