Re: Regarding Netty vulnerability - CVE-2025-24970

2025-04-10 Thread Vijay Mhaskar
Additional information - We are using Solr 9.8.1 and vulnerability is detected in solr-webapp/webapp/WEB-INF/lib/netty-handler-4.1.114.Final.jar. Wanted to check what would be the mitigation for this in Solr*. *Since there is no mention of this CVE on the Solr security page

Regarding Netty vulnerability - CVE-2025-24970

2025-04-09 Thread Vijay Mhaskar
Hello, I’m trying to understand the impact of CVE-2025-24970 , which appears to be related to Netty. I couldn't find any mention of this CVE in the official Solr security page, it's neither listed under exploitable nor in not-exploitable vulnerabili