Package
solr-9-full
Component
jline-builtins
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
The vulnerable JLine classes come from org.apache.hadoop:hadoop-client-runtime's pre-built shaded jar (modules/hdfs/lib/hadoop-client-runtime-3.4.3.jar), where they are relocated to org.apache.hadoop.shaded.org.jline.* and are only reachable through Hadoop's own interactive terminal/shell support (e.g. YARN's ContainerShellWebSocket). solr-9/solr-fips-9 pull in hadoop-client-runtime purely for the HDFS filesystem client backend; Solr's own sources never reference org.jline, terminal, or LineReader anywhere in solr/modules or solr/core -- nothing here constructs a JLine Terminal or invokes the built-in grep/history commands where these CVEs live. No upstream fix is available either: hadoop-client-runtime is frozen at JLine 3.9.0 through the latest Hadoop release (3.5.0), and even Hadoop's unreleased trunk still pins 3.9.0.
Status