[jira] [Commented] (SOLR-15844) Upgrade Velocity to v2.3

2021-12-13 Thread Jira
[ https://issues.apache.org/jira/browse/SOLR-15844?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17458960#comment-17458960 ] Jan Høydahl commented on SOLR-15844: Velocty is gone in 9.0 so this is more to keep u

[GitHub] [solr-site] dsmiley commented on a change in pull request #55: Log4J: Prometheus Exporter isn't vulnerable

2021-12-13 Thread GitBox
dsmiley commented on a change in pull request #55: URL: https://github.com/apache/solr-site/pull/55#discussion_r768262503 ## File path: content/solr/security/2021-12-10-cve-2021-44228.md ## @@ -11,30 +11,21 @@ Critical **Description:** Apache Solr releases prior to 8.11.1 wer

[jira] [Commented] (SOLR-15844) Upgrade Velocity to v2.3

2021-12-13 Thread Gus Heck (Jira)
[ https://issues.apache.org/jira/browse/SOLR-15844?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17458852#comment-17458852 ] Gus Heck commented on SOLR-15844: - TLDR: you've done the work already, so no need to reve

[jira] [Resolved] (SOLR-15843) Update Log4J dependency

2021-12-13 Thread Jira
[ https://issues.apache.org/jira/browse/SOLR-15843?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jan Høydahl resolved SOLR-15843. Resolution: Fixed > Update Log4J dependency > --- > > Key: SOLR

[jira] [Commented] (SOLR-15843) Update Log4J dependency

2021-12-13 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/SOLR-15843?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17458845#comment-17458845 ] ASF subversion and git services commented on SOLR-15843: Commit d

[GitHub] [solr] janhoy merged pull request #457: SOLR-15843: Update Log4J from 2.15 to 2.16

2021-12-13 Thread GitBox
janhoy merged pull request #457: URL: https://github.com/apache/solr/pull/457 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@s

[GitHub] [solr-site] janhoy commented on a change in pull request #55: Log4J: Prometheus Exporter isn't vulnerable

2021-12-13 Thread GitBox
janhoy commented on a change in pull request #55: URL: https://github.com/apache/solr-site/pull/55#discussion_r768251979 ## File path: content/solr/security/2021-12-10-cve-2021-44228.md ## @@ -11,30 +11,21 @@ Critical **Description:** Apache Solr releases prior to 8.11.1 were

[GitHub] [solr] janhoy opened a new pull request #457: SOLR-15843: Update Log4J from 2.15 to 2.16

2021-12-13 Thread GitBox
janhoy opened a new pull request #457: URL: https://github.com/apache/solr/pull/457 https://issues.apache.org/jira/browse/SOLR-15843 https://logging.apache.org/log4j/2.x/changes-report.html#a2.16.0 -- This is an automated message from the Apache Git Service. To respond to the messa

[GitHub] [solr-site] dsmiley opened a new pull request #55: Log4J: Prometheus Exporter isn't vulnerable

2021-12-13 Thread GitBox
dsmiley opened a new pull request #55: URL: https://github.com/apache/solr-site/pull/55 List conversation: https://lists.apache.org/thread/x1qkgyqxtb6mko1qr2qhq40j96q07sy7 Also made references to Log4J consistent in capitalization. -- This is an automated message from the Apache Git S

[jira] [Commented] (SOLR-15843) Update Log4J dependency

2021-12-13 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/SOLR-15843?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17458838#comment-17458838 ] ASF subversion and git services commented on SOLR-15843: Commit c

[jira] [Commented] (SOLR-15843) Update Log4J dependency

2021-12-13 Thread Jira
[ https://issues.apache.org/jira/browse/SOLR-15843?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17458830#comment-17458830 ] Jan Høydahl commented on SOLR-15843: Upgrading further to 2.16 released today: https

[GitHub] [solr-site] dsmiley merged pull request #54: Log4j: Solr's docker images are mitigated.

2021-12-13 Thread GitBox
dsmiley merged pull request #54: URL: https://github.com/apache/solr-site/pull/54 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr.

[jira] [Reopened] (SOLR-15843) Update Log4J dependency

2021-12-13 Thread Jira
[ https://issues.apache.org/jira/browse/SOLR-15843?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jan Høydahl reopened SOLR-15843: Re-opening to bump to 2.16 > Update Log4J dependency > --- > > Key

[jira] [Resolved] (SOLR-15847) Upgrade log4j -> 2.15.0

2021-12-13 Thread Jira
[ https://issues.apache.org/jira/browse/SOLR-15847?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jan Høydahl resolved SOLR-15847. Resolution: Duplicate Please see SOLR-15843. Also see https://solr.apache.org/security.html#apach

[jira] [Created] (SOLR-15847) Upgrade log4j -> 2.15.0

2021-12-13 Thread Roman Kagan (Jira)
Roman Kagan created SOLR-15847: -- Summary: Upgrade log4j -> 2.15.0 Key: SOLR-15847 URL: https://issues.apache.org/jira/browse/SOLR-15847 Project: Solr Issue Type: Improvement Security Level

[jira] [Commented] (SOLR-14444) Ref Guide Redesign Phase 2: Page Organization Overhaul

2021-12-13 Thread Cassandra Targett (Jira)
[ https://issues.apache.org/jira/browse/SOLR-1?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17458675#comment-17458675 ] Cassandra Targett commented on SOLR-1: -- > would it make sense to back port t

[jira] [Commented] (SOLR-14444) Ref Guide Redesign Phase 2: Page Organization Overhaul

2021-12-13 Thread Ishan Chattopadhyaya (Jira)
[ https://issues.apache.org/jira/browse/SOLR-1?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17458461#comment-17458461 ] Ishan Chattopadhyaya commented on SOLR-1: - I was going through this new o

[jira] [Resolved] (SOLR-15843) Update Log4J dependency

2021-12-13 Thread Mike Drob (Jira)
[ https://issues.apache.org/jira/browse/SOLR-15843?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Mike Drob resolved SOLR-15843. -- Resolution: Fixed > Update Log4J dependency > --- > > Key: SOLR-158

[GitHub] [solr] epugh commented on a change in pull request #455: SOLR-15745: Convert corestatus APIs to annotations

2021-12-13 Thread GitBox
epugh commented on a change in pull request #455: URL: https://github.com/apache/solr/pull/455#discussion_r767749071 ## File path: solr/core/src/java/org/apache/solr/handler/admin/CoreAdminHandler.java ## @@ -411,6 +413,8 @@ void call() throws Exception { public Collection

[jira] [Commented] (SOLR-15324) High security vulnerability in Apache Thrift - CVE-2020-13949 (+1) bundled within Solr

2021-12-13 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/SOLR-15324?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17458204#comment-17458204 ] ASF subversion and git services commented on SOLR-15324: Commit f

[jira] [Resolved] (SOLR-15324) High security vulnerability in Apache Thrift - CVE-2020-13949 (+1) bundled within Solr

2021-12-13 Thread Jira
[ https://issues.apache.org/jira/browse/SOLR-15324?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jan Høydahl resolved SOLR-15324. Fix Version/s: 8.11.1 Resolution: Fixed > High security vulnerability in Apache Thrift - CVE

[jira] [Reopened] (SOLR-15324) High security vulnerability in Apache Thrift - CVE-2020-13949 (+1) bundled within Solr

2021-12-13 Thread Jira
[ https://issues.apache.org/jira/browse/SOLR-15324?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jan Høydahl reopened SOLR-15324: > High security vulnerability in Apache Thrift - CVE-2020-13949 (+1) bundled > within Solr > -

[jira] [Commented] (SOLR-15324) High security vulnerability in Apache Thrift - CVE-2020-13949 (+1) bundled within Solr

2021-12-13 Thread Jira
[ https://issues.apache.org/jira/browse/SOLR-15324?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17458197#comment-17458197 ] Jan Høydahl commented on SOLR-15324: PR for 8.11.1 : https://github.com/apache/lucene