10.0.0
15 years ago
2 months ago
Known vulnerabilities in the org.apache.lucene:lucene-queryparser package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the Note: Elasticsearch, although it uses Lucene, is NOT vulnerable to this. How to fix XML External Entity (XXE) Injection? Upgrade | [5.5.0,5.5.5)[6.0.0,6.6.2)[7.0.0,7.1.0) |