Apache Solr官网安全更新(2021-12-16)

情报来源:TSRC

发布时间:2021-12-16

基本信息
  • 发布日期2021-12-16
  • 感知时间2021-12-16
  • 漏洞类型安全更新
  • 风险等级未知
  • 更新版本未知
  • 情报贡献TSRC
更新标题

16 December 2021, Apache Solr™ 8.11.1 available

更新详情

<br/> <br/> The Lucene PMC is pleased to announce the release of Apache Solr 8.11.1.<br/>Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document handling, and geospatial search. Solr is highly scalable, providing fault tolerant distributed search and indexing, and powers the search and navigation features of many of the world&#39;s largest internet sites.<br/>Solr 8.11.1 is available for immediate download at:<br/>https://lucene.apache.org/solr/downloads.html<br/>Solr 8.11.1 Release Highlights:<br/>Security<br/><br/>Updates bundled log4j2 dependencies to address CVE-2021-44228 (SOLR-15843)<br/>Upgrade jaegertracing to 1.6.0 and libthrift to 0.14.1 to address CVE-2020-13949 (SOLR-15324)<br/><br/>Bugfixes<br/><br/>Fixes to the new Admin UI Security and Schema Designer screens (SOLR-15825, SOLR-15774 and SOLR-15813)<br/>Fix regression in 8.11.0 for the Admin UI Files screen and Velocity (SOLR-15804)<br/>Admin endpoints for Zookeeper now by default protected by zk_read permission (SOLR-15768)<br/>Better default security.json uploaded by bin/solr tool (SOLR-15828)<br/>Switching a PRS collection from true -&gt; false -&gt; true resulted in INACTIVE replicas (SOLR-15794)<br/>Fix REPLACENODE to not use source node when choosing a target node (SOLR-15795)<br/>Fix NPE in pivot facets, add non-Analyzed query method in FieldType (SOLR-8319)<br/>Upgrade Velocity from to v2.3 and Velocity Tools to v3.1 (SOLR-15844)<br/>..and more<br/><br/>Please refer to the Upgrade Notes in the Solr Ref Guide for information on upgrading from previous Solr versions:<br/>https://solr.apache.org/guide/8_11/solr-upgrade-notes.html<br/>Please read CHANGES.txt for a full list of bugfixes:<br/>https://solr.apache.org/docs/8_11_1/changes/Changes.html<br/>

软件描述

Apache Solr 是一个开源的搜索服务器。Solr 使用 Java 语言开发,主要基于 HTTP 和 Apache Lucene 实现。Apache Solr 中存储的资源是以 Document 为对象进行存储的。每个文档由一系列的 Field 构成,每个 Field 表示资源的一个属性。

CVE编号

<p><a target="_blank" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228">CVE-2021-44228</a></p><p><a target="_blank" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13949">CVE-2020-13949</a></p>

Knowsafe分析

暂无

业界资讯

暂无

来源链接

https://lucene.apache.org/solr/news.html