-
Notifications
You must be signed in to change notification settings - Fork 140
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2022-42889 - is OpenSearch vulnerable? #485
Comments
ML commons doesn't use anything from |
Another way should be just updating commons-text. It may be possible ml-common will support loading csv data inputs, which depends on CSVLoad in tribuo-data. |
@Craigacp Do you have plan to fix this CVE in tribuo ? We are using |
We released |
Thanks, we will override the version for now. |
CVE-2022-42889 has recently been published. The
opensearch-ml
plugin includes the vulnerablecommons-text:1.9
JAR:(example dependency tree from OpenSearch 1.3.6)
Unfortunately the latest
opencsv
version is still usingcommons-text:1.9
so upstream dependencies can not (yet) easily be patched with just a version bump. A patch foropencsv
has been requested with a comment noting that it does not use the string interpolation feature ofcommons-text
.It would be great if the OpenSearch team could:
The text was updated successfully, but these errors were encountered: