Security Fix for Lucene-core PRISMA-2021-0081 #23688
Draft
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Security fix for Lucene-core
Fixed - 1 High
vulnerable version : 8.2.0
Fixed version : 8.10.0
excluded the higher version because local source build was breaking.
Motivation and Context
Reasons to exclude:
determining the total count for the states of a regex.
Impact
Image scan showed the vulnerability has been removed
Image scan report :
correlation-report-ibm-lh-presto lucene 10th.csv
Test Plan
Tested in 3 form factor : Cpd,Dev and SaaS
Contributor checklist
Release Notes
Please follow release notes guidelines and fill in the release notes below.
If release note is NOT required, use: