Details
-
Task
-
Status: Closed
-
Minor
-
Resolution: Fixed
-
9.1
-
None
Description
This was brought up on the mailing list here: https://lists.apache.org/thread/psc4r75o933y22jos4xk5rcwhof48sdw
The automatically created CVEs against xstream are misleading and read the thread above to try to find out more. Its not clear which CVEs if any are actually valid.
The only one that looks still valid against woodstox-core is CVE-2022-40152 (https://github.com/advisories/GHSA-3f7h-mf4q-vrm4) and fixed in https://github.com/FasterXML/woodstox/issues/160. It is LOW severity only.
Our container scan detects woodstox 6.2.8
/opt/bitnami/solr/server/solr-webapp/webapp/WEB-INF/lib/woodstox-core-6.2.8.jar
Attachments
Attachments
Issue Links
- is duplicated by
-
SOLR-16572 Update FasterXML Woodstox Dependency for CVE-2022-40153
- Resolved
- is related to
-
SOLR-16562 Upgrade to Caffeine 3.1.4
- Closed
- links to