[ 
https://issues.apache.org/jira/browse/SOLR-17833?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Eric Pugh resolved SOLR-17833.
------------------------------
    Fix Version/s: 9.11
       Resolution: Fixed

I am labeling this 9.11, but actually, this gets resolved by publishing a VEX 
file on our Solr website, so it really isn't tied to a "fix version".   But 
maybe this is of most interest to folks when 9.11 comes out?

> Assess expoitability of CVE-2024-7254 in dependency `protobuf-java`
> -------------------------------------------------------------------
>
>                 Key: SOLR-17833
>                 URL: https://issues.apache.org/jira/browse/SOLR-17833
>             Project: Solr
>          Issue Type: Task
>            Reporter: Piotr Karwasz
>            Assignee: Eric Pugh
>            Priority: Major
>              Labels: security
>             Fix For: 9.11
>
>
> h2. Vulnerability Assessment Request
> Please assess the exploitability of the following vulnerability in Apache 
> Solr:
> * *Dependency*: `protobuf-java`
> * *CVE ID*: `CVE-2024-7254`
> * *GHSA ID*: `GHSA-735f-pc8j-v9w8`
> * *Severity*: `high`
> protobuf-java has potential Denial of Service issue
> h3. Context
> This issue was automatically created to track and assess the impact of the 
> reported vulnerability on Apache Solr.
> Please provide your analysis and recommended actions.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to