loftuxab / alfresco-ubuntu-install

Alfresco script based install for Ubuntu
https://loftux.com/products-and-add-ons/alfresco-utilities
166 stars 122 forks source link

CVE-2017-12629 vulnerability reintroduced in solr.in.sh file #115

Closed douglascrp closed 5 years ago

douglascrp commented 5 years ago

The custom version of the https://github.com/loftuxab/alfresco-ubuntu-install/blob/master/search/solr.in.sh reintroduces the CVE-2017-12629 vulnerability that got fixed by Alfresco in the version 1.2.0 of Alfresco Search Service.

This can be easily fixed by including the parameter -Ddisable.configEdit=true in the SOLR_OPTS.

loftux commented 5 years ago

Thanks for this, merged now.