Release 9.0.3(CVE-2021-44228)
Fix for CVE-2021-44228
See: GHSA-jfh8-c2jp-5v3q
[TASK] 2021.12.13 Rebuild Docker images due of(CVE-2021-44228)
There are no actual Docker images for v.7.6 provided with fixed CVE-2021-44228.
See docker-solr/docker-solr#282
Therefore we updating the EXT:solr images to upstream Apache Solr 7.7 images.
The community in TYPO3 Slacks ext-solr channel did it few times, whiteout reporting any issues.
Note: If you are not on docker, the update to Apache Solr 7.7 not required but applying the workarounds described in https://solr.apache.org/security.html#apache-solr-affected-by-apache-log4j-cve-2021-44228
Please refer for certain workaround and updates: https://www.dkd.de/de/blog/sicherheitsluecke-in-log4j-security-incident-in-log4j/
New in this release:
- [BUGFIX] Remove usage of deprecated method getCoreName in IndexAdministrationModuleController (#2287)
- [BUGFIX] Do not quote integer values for flexform filters (#2297)
- [BUGFIX] Set value of grouping.numberOfGroups (#2357)
- [TASK] Dispatch signals in OptionsFacetParser (#2356)
- [FEATURE] Provide arguments in results view (#2352)
- [BUGFIX] Initialize TSFE on 2nd level cache hit (#2331)
- [BUGFIX] Respect TableMapping parameter (#2313)
- [BUGFIX] don't remove content that is visible to the user (9.0.x) (#2366)
- [TASK] Trigger indexqueue update when moving records (#2431)
- [BUGFIX] configuration status domain records (#2377)
- [BUGFIX:BACKPORT:9] Add facet name to facet filters (#2343)
- [BUGFIX] Initialize TSFE, if conf of page was cached
- Update SolrNotAvailable.html (#3020)