-
Notifications
You must be signed in to change notification settings - Fork 916
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2022-37603 (High) detected in loader-utils-2.0.3 #3306
Comments
CVE-2022-37603 and CVE-2022-37599 Analysis
Github Issue: #2612
Github issue: #2560
We did bump it to 2.0.3 in this PR (backport PR to 2.x):
We bump the version to 2.0.4 in this PR: Fixes and action item:
2.0.4 is the target version. We did bump the version to 2.0.4 in this PR in main: If there is no breaking changes, we will backport the PR to bump the version. |
Currently only 2.x is using 2.0.3
|
We will backport to 2.x and 2.5 |
Issue Resolved: opensearch-project#3306 Signed-off-by: Anan Zhuang <ananzh@amazon.com>
Issue Resolved: opensearch-project#3306 Signed-off-by: Anan Zhuang <ananzh@amazon.com>
Issue Resolved: opensearch-project#3306 Signed-off-by: Anan Zhuang <ananzh@amazon.com>
Issue Resolved: opensearch-project#3306 Signed-off-by: Anan Zhuang <ananzh@amazon.com>
Issue Resolved: opensearch-project#3306 Signed-off-by: Anan Zhuang <ananzh@amazon.com>
Issue Resolved: opensearch-project#3306 Signed-off-by: Anan Zhuang <ananzh@amazon.com>
Issue Resolved: #3306 Signed-off-by: Anan Zhuang <ananzh@amazon.com> Signed-off-by: Anan Zhuang <ananzh@amazon.com>
CVE-2022-46175 - High Severity Vulnerability
Vulnerability Library - loader-utils - 2.0.3
CVSS 3 Score Details - (7.5)
Suggested Fix
Type: Upgrade version
Release Date: Oct 6, 2022
Fix Resolution: loader-utils - 2.0.4
More Info
loader-utils issue resolved with #213
The text was updated successfully, but these errors were encountered: