./textproc/solr [full-text search engine based on Lucene]
[+] Add this package to your ports tracker

[ CVSweb ] [ Homepage ] [ RSS feed ]

Version: 7.4.0, Package name: solr-7.4.0
Maintained by: The OpenBSD ports mailing-list
Master sites:
Description
Solr is a standalone enterprise search server with a REST-like API
supporting JSON, XML, CSV or binary over HTTP for document addition
and searches.


Filesize: 163424.693 KB
Version History (View Complete History)
  • (2018-06-23) Updated to version: solr-7.4.0
  • (2018-05-24) Updated to version: solr-7.3.1
  • (2018-04-10) Updated to version: solr-7.3.0
  • (2018-03-06) Package added to openports.se, version solr-7.2.1 (created)
[show/hide] View available PLISTS (Can be a lot of data)

CVS Commit History:

   2018-06-23 08:55:04 by Stuart Henderson | Files touched by this commit (5)
Log message:
update to solr-7.4.0
   2018-06-23 08:55:04 by Stuart Henderson | Files touched by this commit (5)
Log message:
update to solr-7.4.0
   2018-06-23 08:55:04 by Stuart Henderson | Files touched by this commit (5)
Log message:
update to solr-7.4.0
   2018-06-23 08:55:04 by Stuart Henderson | Files touched by this commit (5)
Log message:
update to solr-7.4.0
   2018-06-23 08:55:04 by Stuart Henderson | Files touched by this commit (5)
Log message:
update to solr-7.4.0
   2018-05-24 04:25:28 by Stuart Henderson | Files touched by this commit (3)
Log message:
update to solr-7.3.1,
CVE-2018-8010: XXE vulnerability due to Apache Solr configset upload
   2018-05-24 04:24:37 by Stuart Henderson | Files touched by this commit (3)
Log message:
update to solr-7.3.1, if you aren't restricting to local-only traffic
then you probably want this ..
CVE-2018-8010: XXE vulnerability due to Apache Solr configset upload
   2018-05-24 04:24:37 by Stuart Henderson | Files touched by this commit (3)
Log message:
update to solr-7.3.1, if you aren't restricting to local-only traffic
then you probably want this ..
CVE-2018-8010: XXE vulnerability due to Apache Solr configset upload
   2018-05-24 04:24:37 by Stuart Henderson | Files touched by this commit (3)
Log message:
update to solr-7.3.1, if you aren't restricting to local-only traffic
then you probably want this ..
CVE-2018-8010: XXE vulnerability due to Apache Solr configset upload
   2018-04-10 06:22:39 by Stuart Henderson | Files touched by this commit (4)
Log message:
security update to solr-7.3.0
CVE-2018-1308: XXE attack through Apache Solr's DIH's dataConfig request parameter
This vulnerability relates to an XML external entity expansion (XXE) in the
`&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be
used as XXE using file/ftp/http protocols in order to read arbitrary local
files from the Solr server or the internal network. See [1] for more details.
Mitigation:
Users are advised to upgrade to either Solr 6.6.3 or Solr 7.3.0 releases both
of which address the vulnerability. Once upgrade is complete, no other steps
are required. Those releases disable external entities in anonymous XML files
passed through this request parameter.
If users are unable to upgrade to Solr 6.6.3 or Solr 7.3.0 then they are
advised to disable data import handler in their solrconfig.xml file and
restart their Solr instances. Alternatively, if Solr instances are only used
locally without access to public internet, the vulnerability cannot be used
directly, so it may not be required to update, and instead reverse proxies or
Solr client applications should be guarded to not allow end users to inject
`dataConfig` request parameters.
   2018-04-10 06:22:39 by Stuart Henderson | Files touched by this commit (4)
Log message:
security update to solr-7.3.0
CVE-2018-1308: XXE attack through Apache Solr's DIH's dataConfig request parameter
This vulnerability relates to an XML external entity expansion (XXE) in the
`&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be
used as XXE using file/ftp/http protocols in order to read arbitrary local
files from the Solr server or the internal network. See [1] for more details.
Mitigation:
Users are advised to upgrade to either Solr 6.6.3 or Solr 7.3.0 releases both
of which address the vulnerability. Once upgrade is complete, no other steps
are required. Those releases disable external entities in anonymous XML files
passed through this request parameter.
If users are unable to upgrade to Solr 6.6.3 or Solr 7.3.0 then they are
advised to disable data import handler in their solrconfig.xml file and
restart their Solr instances. Alternatively, if Solr instances are only used
locally without access to public internet, the vulnerability cannot be used
directly, so it may not be required to update, and instead reverse proxies or
Solr client applications should be guarded to not allow end users to inject
`dataConfig` request parameters.
   2018-04-10 06:22:39 by Stuart Henderson | Files touched by this commit (4)
Log message:
security update to solr-7.3.0
CVE-2018-1308: XXE attack through Apache Solr's DIH's dataConfig request parameter
This vulnerability relates to an XML external entity expansion (XXE) in the
`&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be
used as XXE using file/ftp/http protocols in order to read arbitrary local
files from the Solr server or the internal network. See [1] for more details.
Mitigation:
Users are advised to upgrade to either Solr 6.6.3 or Solr 7.3.0 releases both
of which address the vulnerability. Once upgrade is complete, no other steps
are required. Those releases disable external entities in anonymous XML files
passed through this request parameter.
If users are unable to upgrade to Solr 6.6.3 or Solr 7.3.0 then they are
advised to disable data import handler in their solrconfig.xml file and
restart their Solr instances. Alternatively, if Solr instances are only used
locally without access to public internet, the vulnerability cannot be used
directly, so it may not be required to update, and instead reverse proxies or
Solr client applications should be guarded to not allow end users to inject
`dataConfig` request parameters.
   2018-04-10 06:22:39 by Stuart Henderson | Files touched by this commit (4)
Log message:
security update to solr-7.3.0
CVE-2018-1308: XXE attack through Apache Solr's DIH's dataConfig request parameter
This vulnerability relates to an XML external entity expansion (XXE) in the
`&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be
used as XXE using file/ftp/http protocols in order to read arbitrary local
files from the Solr server or the internal network. See [1] for more details.
Mitigation:
Users are advised to upgrade to either Solr 6.6.3 or Solr 7.3.0 releases both
of which address the vulnerability. Once upgrade is complete, no other steps
are required. Those releases disable external entities in anonymous XML files
passed through this request parameter.
If users are unable to upgrade to Solr 6.6.3 or Solr 7.3.0 then they are
advised to disable data import handler in their solrconfig.xml file and
restart their Solr instances. Alternatively, if Solr instances are only used
locally without access to public internet, the vulnerability cannot be used
directly, so it may not be required to update, and instead reverse proxies or
Solr client applications should be guarded to not allow end users to inject
`dataConfig` request parameters.