Package
solr-9-iamguarded-compat
Component
jetty-http
Latest update
7.4
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Copied from solr-9 advisory CGA-jq27-fp76-r825
Original note: Solr 9.x embeds Jetty 10.x (10.0.26 is the final 10.x release, now EOL). This CVE has no fix available for Jetty 10.x; the fix is only in Jetty 12.0.31+. Jetty 12 introduces breaking API changes and restructured artifacts (e.g., jetty-ee10-* modules) that require significant code changes in Solr itself — a drop-in version bump is not possible. Solr 10.x has already migrated to Jetty 12, but backporting that migration to Solr 9.x is not feasible. Waiting for upstream to release a Solr 9.x patch that upgrades the embedded Jetty.
Status