Multiple vulnerabilities in Apache Solr dependency
Issue date: 27-10-2020Affects versions: 14.2, 13.4, 12.6
Issue ID: SECURITY-148
Affected Product Version(s)
14.2.2, 13.4.3, 12.6.10 (and previous patch releases)
Severity
low
Description
Previous versions of brXM contained an example integration with Apache Solr using an outdated version of Solr dependencies that contained multiple reported vulnerabilities. This function was not exposed by the brXM product directly, but could have been used by a customer project.
See: List of reported Apache Solr vulnerabilities and the upgrade notes for the relevant brXM version.
This example integration has been removed, along with the vulnerable dependencies, in all our latest supported versions: 14.3.0, 13.4.4 and 12.6.11.
Instructions
Customers are recommended to upgrade to the latest maintenance or minor releases as indicated above. This can be done by simply incrementing the version number of the parent POM for the implementation project.