Skip to content

Release 9.0.3(CVE-2021-44228)

Compare
Choose a tag to compare
@dkd-kaehm dkd-kaehm released this 13 Dec 14:56

Fix for CVE-2021-44228

See: GHSA-jfh8-c2jp-5v3q

[TASK] 2021.12.13 Rebuild Docker images due of(CVE-2021-44228)

There are no actual Docker images for v.7.6 provided with fixed CVE-2021-44228.
See docker-solr/docker-solr#282
Therefore we updating the EXT:solr images to upstream Apache Solr 7.7 images.
The community in TYPO3 Slacks ext-solr channel did it few times, whiteout reporting any issues.

Note: If you are not on docker, the update to Apache Solr 7.7 not required but applying the workarounds described in https://solr.apache.org/security.html#apache-solr-affected-by-apache-log4j-cve-2021-44228

Please refer for certain workaround and updates: https://www.dkd.de/de/blog/sicherheitsluecke-in-log4j-security-incident-in-log4j/


New in this release:

  • [BUGFIX] Remove usage of deprecated method getCoreName in IndexAdministrationModuleController (#2287)
  • [BUGFIX] Do not quote integer values for flexform filters (#2297)
  • [BUGFIX] Set value of grouping.numberOfGroups (#2357)
  • [TASK] Dispatch signals in OptionsFacetParser (#2356)
  • [FEATURE] Provide arguments in results view (#2352)
  • [BUGFIX] Initialize TSFE on 2nd level cache hit (#2331)
  • [BUGFIX] Respect TableMapping parameter (#2313)
  • [BUGFIX] don't remove content that is visible to the user (9.0.x) (#2366)
  • [TASK] Trigger indexqueue update when moving records (#2431)
  • [BUGFIX] configuration status domain records (#2377)
  • [BUGFIX:BACKPORT:9] Add facet name to facet filters (#2343)
  • [BUGFIX] Initialize TSFE, if conf of page was cached
  • Update SolrNotAvailable.html (#3020)