Skip to content

Commit 60e3fa9

Browse files
Lucene Package Update to Address CVE-2024-43383 (#17942)
* Update Lucene Package to 4.8.0-beta00017 * Add Package Reference --------- Co-authored-by: Sebastiaan Janssen <[email protected]>
1 parent fd1bd51 commit 60e3fa9

File tree

2 files changed

+5
-1
lines changed

2 files changed

+5
-1
lines changed

Directory.Packages.props

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -91,11 +91,13 @@
9191
<PackageVersion Include="System.Text.RegularExpressions" Version="4.3.1" />
9292
<!-- Both OpenIddict.AspNetCore, Npoco.SqlServer and Microsoft.EntityFrameworkCore.SqlServer bring in a vulnerable version of Microsoft.IdentityModel.JsonWebTokens -->
9393
<PackageVersion Include="Microsoft.IdentityModel.JsonWebTokens" Version="7.7.1" />
94+
<!-- Examine.Lucene bring in a vulnerable version of Lucene.Net.Replicator -->
95+
<PackageVersion Include="Lucene.Net.Replicator" Version="4.8.0-beta00017" />
9496
<!-- Both OpenIddict.AspNetCore, Microsoft.EntityFrameworkCore.* bring in a vulnerable version of Microsoft.Extensions.Caching.Memory -->
9597
<PackageVersion Include="Microsoft.Extensions.Caching.Memory" Version="8.0.1" />
9698
<!-- Both Azure.Identity, Microsoft.EntityFrameworkCore.SqlServer,NPoco.SqlServer, and more bring in a vulnerable version of System.Text.Json -->
9799
<PackageVersion Include="System.Text.Json" Version="8.0.5" />
98100
<!-- Both Microsoft.EntityFrameworkCore.SqlServer and NPoco.SqlServer bring in a vulnerable version of Microsoft.Data.SqlClient -->
99101
<PackageVersion Include="Microsoft.Data.SqlClient" Version="5.2.2" />
100102
</ItemGroup>
101-
</Project>
103+
</Project>

src/Umbraco.Examine.Lucene/Umbraco.Examine.Lucene.csproj

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,8 @@
1010
<PackageReference Include="Examine" />
1111
<!-- Take top-level depedendency on System.Security.Cryptography.Xml, because Examine depends on a vulnerable version -->
1212
<PackageReference Include="System.Security.Cryptography.Xml" />
13+
<!-- Take top-level depedendency on Lucene.Net.Replicator-->
14+
<PackageReference Include="Lucene.Net.Replicator" />
1315
</ItemGroup>
1416

1517
<ItemGroup>

0 commit comments

Comments
 (0)