Package
solr-fips-9-full
Component
jackson-core
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable jackson classes are shaded into the hadoop-client-runtime 3.4.3 jar that the hdfs module ships, so Solr's jackson-bom constraint cannot replace them; Solr's own jackson is already on 2.18.9. The Hadoop 3.4.x line that Solr 9.x builds against bundles jackson 2.12.7. Remediation requires a Solr 9.x release that adopts a Hadoop release bundling a fixed jackson.
Status
Previous location
/usr/share/java/solr/modules/hdfs/lib/hadoop-client-runtime-3.4.1.jarNew location
/usr/share/java/solr/modules/hdfs/lib/hadoop-client-runtime-3.4.3.jarImpact
version-only path change detected during APK rebuild
Status