Re: Antw: Solr Image 8.11.2 susceptible to CVE-2021-31879 and GHSA-jgvc-jfgh-rjvv

2023-08-22 Thread Pieper, Stefan
Thanks a lot! That helps and is a true pain relief. From: Jan Høydahl Date: Tuesday, 22. August 2023 at 00:29 To: users@solr.apache.org Subject: Re: Antw: Solr Image 8.11.2 susceptible to CVE-2021-31879 and GHSA-jgvc-jfgh-rjvv Hi, The jose4j attack would affect the `jwt-auth` module, but only

Re: Antw: Solr Image 8.11.2 susceptible to CVE-2021-31879 and GHSA-jgvc-jfgh-rjvv

2023-08-21 Thread Jan Høydahl
rmation from the Solr team that > this is a "false positive" and Solr is not affected at all. > > Best > Stefan > > From: Thomas Heldmann > Date: Monday, 21. August 2023 at 14:26 > To: users@solr.apache.org > Subject: Antw: Solr Image 8.11.2 susceptible to CVE-2021-3

Re: Antw: Solr Image 8.11.2 susceptible to CVE-2021-31879 and GHSA-jgvc-jfgh-rjvv

2023-08-21 Thread Pieper, Stefan
ot;moderate"). I am hoping for confirmation from the Solr team that this is a "false positive" and Solr is not affected at all. Best Stefan From: Thomas Heldmann Date: Monday, 21. August 2023 at 14:26 To: users@solr.apache.org Subject: Antw: Solr Image 8.11.2 susceptible to

Antw: Solr Image 8.11.2 susceptible to CVE-2021-31879 and GHSA-jgvc-jfgh-rjvv

2023-08-21 Thread Thomas Heldmann
Dear Mr Pieper, Do these security issues only affect Solr Docker image 8.11.2 or also Solr installations on local computers and SolrCloud installations on servers (= Solr Clusters)? Best regards, Thomas Heldmann -- Thomas Heldmann Bayerische Staatsbibliothek Verbundzentrale des Bibliotheksver