Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] GHSA-6g3j-p5g6-992f #3837

Closed
dlvenable opened this issue Dec 8, 2023 · 1 comment · Fixed by #3838
Closed

[BUG] GHSA-6g3j-p5g6-992f #3837

dlvenable opened this issue Dec 8, 2023 · 1 comment · Fixed by #3838
Assignees
Labels
bug Something isn't working
Milestone

Comments

@dlvenable
Copy link
Member

Describe the bug

OpenSearch has a security advisory. It is related to the _search API. But, we should update to avoid the CVE.

See advisory:

GHSA-6g3j-p5g6-992f

@dlvenable dlvenable added bug Something isn't working untriaged labels Dec 8, 2023
dlvenable added a commit to dlvenable/data-prepper that referenced this issue Dec 8, 2023
…t 1.3.14 as well. Resolves opensearch-project#3837.

Signed-off-by: David Venable <dlv@amazon.com>
dlvenable added a commit to dlvenable/data-prepper that referenced this issue Dec 8, 2023
…t 2.11.1 and 1.3.14 as well. Resolves opensearch-project#3837.

Signed-off-by: David Venable <dlv@amazon.com>
@dlvenable dlvenable self-assigned this Dec 8, 2023
@dlvenable dlvenable added this to the v2.6.2 milestone Dec 8, 2023
@dlvenable
Copy link
Member Author

Waiting on the release of OpenSearch 1.3.14.

opensearch-project/opensearch-build#4069

dlvenable added a commit that referenced this issue Dec 19, 2023
…t 2.11.1 and 1.3.14 as well. Resolves #3837. (#3838)

Signed-off-by: David Venable <dlv@amazon.com>
@github-project-automation github-project-automation bot moved this from Unplanned to Done in Data Prepper Tracking Board Dec 19, 2023
opensearch-trigger-bot bot pushed a commit that referenced this issue Dec 19, 2023
…t 2.11.1 and 1.3.14 as well. Resolves #3837. (#3838)

Signed-off-by: David Venable <dlv@amazon.com>
(cherry picked from commit df2bde6)
dlvenable added a commit that referenced this issue Jan 2, 2024
…t 2.11.1 and 1.3.14 as well. Resolves #3837. (#3838) (#3862)

Signed-off-by: David Venable <dlv@amazon.com>
(cherry picked from commit df2bde6)

Co-authored-by: David Venable <dlv@amazon.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
Development

Successfully merging a pull request may close this issue.

1 participant