Debian LTS: DLA-1360-1: lucene-solr security update
Summary
We recommend that you upgrade your lucene-solr packages.
Regards,
- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-
Package : lucene-solr Version : 3.6.0+dfsg-1+deb7u4 CVE ID : CVE-2018-1308 Debian Bug : #896604 It was discovered that there was an XML external entity expansion (XXE) vulnerability in lucene-solr, a search engine library for Java. It could be exploited to read arbitrary local files from the Solr server or the internal network. For Debian 7 "Wheezy", this issue has been fixed in lucene-solr version 3.6.0+dfsg-1+deb7u4. We recommend that you upgrade your lucene-solr packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` lamby@debian.org / chris-lamb.co.uk `-
We recommend that you upgrade your lucene-solr packages.
Regards,
- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-