Re: Reg CVE 2021-44832

2023-09-06 Thread ramkrishna vasudevan
Thanks a lot Shawn. I do apologize for cross posting it though. Sometimes dev community and the PMCs are more closer to the security items hence I did send to both. But i totally agree with you. Next time will send it to security@ mailing list. But your answer to this was very useful to us. Regar

Re: Reg CVE 2021-44832

2023-09-06 Thread Shawn Heisey
On 9/5/23 23:10, ramkrishna vasudevan wrote: Now the tools that we run internally flags CVE-2021-44832 . I did not notice that this was cross-posted to both users and dev. I read dev first, replied, and then saw this message. This list (users

Reg CVE 2021-44832

2023-09-05 Thread ramkrishna vasudevan
Hi All, We are internally using Solr 7.5. As part of the zero day log4j vulnerability we already moved the log4j to 2.17.0 version in the solr component. Now the tools that we run internally flags CVE-2021-44832 . But the Solr security page https:/