Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability: CVE-2022-42003 & CVE-2022-42889 in opensearchproject/opensearch:1.3.6 #5094

Closed
jefftyn opened this issue Nov 5, 2022 · 5 comments
Labels
bug Something isn't working distributed framework

Comments

@jefftyn
Copy link

jefftyn commented Nov 5, 2022

Describe the bug

Hi team,

In our trivy scan report there are 1 HIGH and 1 CRITICAL vulnerabilities in opensearchproject/opensearch:1.3.6.
Is there any plan to upgrade the version of libs to fix them? Thanks.

Library Vulnerability Severity Installed Version Fixed Version Title
com.fasterxml.jackson.core:jackson-databind(jackson-databind-2.13.2.2.jar) CVE-2022-42003 HIGH 2.13.2.2 2.12.7.1, 2.13.4.1 jackson-databind: deep wrapper array nesting wrt(jackson-databind-2.13.2.2.jar) UNWRAP_SINGLE_VALUE_ARRAYS https://avd.aquasec.com/nvd/cve-2022-42003
org.apache.commons:commons-text (commons-text-1.9.jar) CVE-2022-42889 CRITICAL 1.9 1.10.0 apache-commons-text: variable interpolation RCE https://avd.aquasec.com/nvd/cve-2022-42889
@jefftyn jefftyn added bug Something isn't working untriaged labels Nov 5, 2022
@andrross
Copy link
Member

andrross commented Nov 7, 2022

@jefftyn The next 1.3 release is scheduled for December 8 and will include these fixes

@anasalkouz
Copy link
Member

Closing this, since they are already fixed and will be pushed on next release.

@colmaengus
Copy link

When is the next release due? Our security folks are starting to complain.

@reta
Copy link
Collaborator

reta commented Nov 28, 2022

@colmaengus https://opensearch.org/releases.html

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working distributed framework
Projects
None yet
Development

No branches or pull requests

5 participants