-
Notifications
You must be signed in to change notification settings - Fork 1.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Snakeyaml vulnerability in OpenSearch 2.2.1 #5614
Comments
I think OpenSearch core is not affected by the CVE-2022-1471. Although Seeing from the CVE description, the mitigation is to use alternative API, instead of upgrading the version. While to mute the alert from security scanners, the version of In addition, Security Analytics plugin may be affected by the vulnerability, which is not part of this code repository, and the fix will go in 2.5.0 release on Jan 17, 2023, see the PR #5576 for detail. I will close the issue, please free to reopen if you have further questions. |
Update on April 2023:
|
Opensearch 2.2.1 has a dependency on vulnerable Snakeyaml version 1.26.
Dependency Hierarchy:
-> opensearch-2.2.1-SNAPSHOT.jar (Root Library)
-> opensearch-x-content-2.2.1-SNAPSHOT.jar
Please check details of the WhiteSource scan here
This is a CI blocker in case changes are required in plugin bundled with core 2.2.x.
The text was updated successfully, but these errors were encountered: