CVE-2022-40153 com.fasterxml.woodstox_woodstox-core

2022-11-22 Thread Billy Kidwell
Our container scan found a potential security vulnerability in Solr 9.0.0 and 9.1.0 for woodstox-core. I checked the security page, the official list of non-exploitable vulnerabilities and the user mailing list. For 9.1.0, the package version seems to be 6.2.8 /solr/server/solr-webapp/webapp/W

CVE-2022-40153 com.fasterxml.woodstox_woodstox-core

2022-11-29 Thread Billy Kidwell
https://nvd.nist.gov/vuln/detail/CVE-2022-40153 Our container scan found a potential security vulnerability in Solr 9.0.0 and 9.1.0 for woodstox-core. I checked the security page, the official list of non-exploitable vulnerabilities and the user mailing list. I also checked jira. There are a