You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The repository-s3 plugin has an external dependency third-party-jackson-core that has a Sonatype vulnerability (sonatype-2022-6438). This got fixed in the version 2.15 and got integrated into AWS JDK version 2.20.140.
OpenSearch is still (as of version 3) being built using AWS JDK version 2.20.86 is causing the vulnerability to be flagged by Sonatype.
Related component
Build
To Reproduce
N/A
Expected behavior
N/A
Additional Details
Plugins
standard + repository-s3.
The text was updated successfully, but these errors were encountered:
Describe the bug
The repository-s3 plugin has an external dependency third-party-jackson-core that has a Sonatype vulnerability (sonatype-2022-6438). This got fixed in the version 2.15 and got integrated into AWS JDK version 2.20.140.
OpenSearch is still (as of version 3) being built using AWS JDK version 2.20.86 is causing the vulnerability to be flagged by Sonatype.
Related component
Build
To Reproduce
N/A
Expected behavior
N/A
Additional Details
Plugins
standard + repository-s3.
The text was updated successfully, but these errors were encountered: