-
Notifications
You must be signed in to change notification settings - Fork 1.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[BUG] Update aws-java-sdk-s3 to >1.12.261 #4161
Comments
Looks like dependencies were upgraded in |
@kartg looks like a high sev CVE, can we get this to 2.2 ? |
@peterzhuamazon have we started building the 2.2 release yet? Or can we get this CVE fix in? I'll work on the manual backport to 2.x in the meantime. cc @CEHENKLE |
@kartg we have seen some issues in PA/SQL Workbench now so you are safe to backport your change. Thanks. |
Just confirming that we're pulling this upgrade into the |
Thank you! |
Closing this issue since the library upgrade was merged to the 2.2 branch with #4166 |
opensearch 2.1.0 contains com.amazonaws_aws-java-sdk-s3 v1.11.749 which has this security advisory published for it: GHSA-c28r-hw5m-5gv3
CVE-2022-31159
Please can OS bump its use of that plugin to > 1.12.261 to pick up the fix ?
The text was updated successfully, but these errors were encountered: