SOLR CVE Update Apache Calcite Driver

2022-11-03 Thread Joseph Gonzalez
Hello, My project security team ran a scan against a SOLR 8.11.1 Docker Image and found a couple vulnerabilities that they recommended I open tickets for. Apache Calcite Driver CVE-2022-36364 Apache Avatica Core CVE-2022-39135 Zlib CVE-2022-37434 Thanks, Joe

RE: Re: SOLR CVE Update Apache Calcite Driver

2022-11-03 Thread Joseph Gonzalez
gt; > 2. nov. 2022 kl. 21:31 skrev Joseph Gonzalez > > mailto:jg...@reingold.com>>: > > > > Hello, > > > > My project security team ran a scan against a SOLR 8.11.1 Docker Image and > > found a couple vulnerabilities that they recommended I open tickets fo

Backport Netty 4.1.87.Final to Solr 8.11.3

2023-01-20 Thread Joseph Gonzalez
Hello, I saw that Netty 4.1.87.Final was brought into SOLR 9.2 via https://issues.apache.org/jira/browse/SOLR-16626. Can that change be backported to Solr 8.11.3 to resolve CVE-2022-41881? Thanks, Joe