[
https://issues.apache.org/jira/browse/SOLR-10702?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18103874#comment-18103874
]
Eric Pugh commented on SOLR-10702:
----------------------------------
this has been done... i am going to create a VEX file though that covers
**CVE-2022-40152** which was impacting one of the Woodstox versions that Solr
had, though long since fixed.
> Woodstox API
> -------------
>
> Key: SOLR-10702
> URL: https://issues.apache.org/jira/browse/SOLR-10702
> Project: Solr
> Issue Type: Bug
> Components: Build
> Affects Versions: 5.5.1, 6.5.1
> Reporter: Rong Chen
> Priority: Major
>
> similar situation to SOLR-5064, woodstox api has artifact id change from
> woodstox-core-asl to woodstox-core and upgrade version for woodstox-core-asl
> 4.4.1 becomes woodstox-core 5.x.
> according to
> https://issues.apache.org/jira/browse/SOLR-5064?focusedCommentId=15535974&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#comment-15535974
> would you please confirm if woodstox-core-asl can be safely excluded from
> dependency of solr*?
> if not, what is the plan to upgrade solr dependency from woodstox-core-asl to
> woodstox-core?
> Thanks.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]