Multiple vulnerabilities in Apache Solr dependency 

Issue date: 27-10-2020
Affects versions: 14.2, 13.4, 12.6

Issue ID: SECURITY-148

Affected Product Version(s)
14.2.2, 13.4.3, 12.6.10 (and previous patch releases)

Severity 
low

Description

Previous versions of brXM contained an example integration with Apache Solr using an outdated version of Solr dependencies that contained multiple reported vulnerabilities. This function was not exposed by the brXM product directly, but could have been used by a customer project.

See: List of reported Apache Solr vulnerabilities and the upgrade notes for the relevant brXM version.

This example integration has been removed, along with the vulnerable dependencies, in all our latest supported versions: 14.3.0, 13.4.4 and 12.6.11.

Instructions

Customers are recommended to upgrade to the latest maintenance or minor releases as indicated above. This can be done by simply incrementing the version number of the parent POM for the implementation project.