Re: Apache Solr 8.11.1 and Log4J Vulnerability

2022-04-14 Thread Shawn Heisey
On 4/14/2022 7:18 PM, Shawn Heisey wrote: https://paste.elyograg.org/view/ed0f1b1e The required steps are found in the first 33 lines.  The remaining 43000 lines is the whole build. To be very specific, the commands I did are on lines 1, 9, 10, 14, 32, and 33.

Re: Apache Solr 8.11.1 and Log4J Vulnerability

2022-04-14 Thread Shawn Heisey
On 4/14/2022 6:14 PM, Shawn Heisey wrote: If you need to check a compliance box saying you dealt with a nonexistent vulnerability, just replace the jars as I already said. If you want to get really adventurous, you could clone the git repo, check out branch_8_11, and build it yourself.  That

Re: Apache Solr 8.11.1 and Log4J Vulnerability

2022-04-14 Thread Shawn Heisey
On 4/14/2022 11:59 AM, Tate, Justina (DTMB) wrote: Can you please explain how we can go about upgrading Log4J to greater than 2.16.0. Just replace the jars in the Solr install directory with newer versions obtained directly from the log4j project. But there's no need.  Solr is not vulnerabl

Apache Solr 8.11.1 and Log4J Vulnerability

2022-04-14 Thread Tate, Justina (DTMB)
Hello, Can you please explain how we can go about upgrading Log4J to greater than 2.16.0. Thank you, Justina Tate , MBA Senior IT Business Analyst Michigan Department of Technology, Management & Budget Agency Services supporting Attorney General and MSHDA 201 N. Washington Square, Ste. 900, Lan