[Backport 2.x] Fix serialization of nested aggregates under SingleBucketAggregateBase
(#1350)
#1352
+26
−1
Mend for GitHub.com / WhiteSource Security Check
failed
Dec 11, 2024 in 6m 16s
Security Report
1 new vulnerabilities were introduced in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-7254Path to dependency file: /java-client/build.gradle.kts Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.google.protobuf/protobuf-java/3.22.3/fdee98b8f6abab73f146a4edb4c09e56f8278d03/protobuf-java-3.22.3.jar Dependency Hierarchy: -> framework-2.12.0.jar (Root Library) -> opensearch-2.12.0.jar -> ❌ protobuf-java-3.22.3.jar (Vulnerable Library) |
High | 7.5 | protobuf-java-3.22.3.jar | Upgrade to version: com.google.protobuf:protobuf-javalite - 3.25.5,4.28.2,4.27.5;com.google.protobuf:protobuf-java - 4.27.5,3.25.5,4.28.2 | None |
Base branch total remaining vulnerabilities: 0
Base branch commit: b07eae54ccdb18ddb6347448400e3c29f5f1a7a8
Total libraries scanned: 235
Scan token: c77fbfeb798343dd8ebecd688c705a34
Loading