Skip to content

Commit

Permalink
opensearch-2: advisory entry for bouncycastle CVEs (#5099)
Browse files Browse the repository at this point in the history
Signed-off-by: hectorj2f <hector@chainguard.dev>
  • Loading branch information
hectorj2f authored May 30, 2024
1 parent d5728a0 commit 52c4fbb
Showing 1 changed file with 16 additions and 0 deletions.
16 changes: 16 additions & 0 deletions opensearch-2.advisories.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -162,6 +162,10 @@ advisories:
componentType: java-archive
componentLocation: /usr/share/opensearch/lib/tools/plugin-cli/bc-fips-1.0.2.4.jar
scanner: grype
- timestamp: 2024-05-30T23:00:31Z
type: pending-upstream-fix
data:
note: The subpackage opensearch-performance-analyzer compilation hardcodes the cloning a specific branch of opensearch-performance-analyzer-rca repository with the vulnerable libraries. This requires upstream changes to opensearch-performance-analyzer-rca repository.

- id: CGA-35r6-m6p6-xc93
aliases:
Expand All @@ -180,6 +184,10 @@ advisories:
componentType: java-archive
componentLocation: /usr/share/opensearch/plugins/opensearch-identity-shiro/bcprov-jdk18on-1.77.jar
scanner: grype
- timestamp: 2024-05-30T23:00:31Z
type: pending-upstream-fix
data:
note: The subpackage opensearch-performance-analyzer compilation hardcodes the cloning a specific branch of opensearch-performance-analyzer-rca repository with the vulnerable libraries. This requires upstream changes to opensearch-performance-analyzer-rca repository.

- id: CGA-h94h-f38q-chh8
aliases:
Expand All @@ -198,6 +206,10 @@ advisories:
componentType: java-archive
componentLocation: /usr/share/opensearch/plugins/opensearch-identity-shiro/bcprov-jdk18on-1.77.jar
scanner: grype
- timestamp: 2024-05-30T23:00:31Z
type: pending-upstream-fix
data:
note: The subpackage opensearch-performance-analyzer compilation hardcodes the cloning a specific branch of opensearch-performance-analyzer-rca repository with the vulnerable libraries. This requires upstream changes to opensearch-performance-analyzer-rca repository.

- id: CGA-2wgv-29fq-xg2j
aliases:
Expand All @@ -216,3 +228,7 @@ advisories:
componentType: java-archive
componentLocation: /usr/share/opensearch/plugins/opensearch-identity-shiro/bcprov-jdk18on-1.77.jar
scanner: grype
- timestamp: 2024-05-30T23:00:31Z
type: pending-upstream-fix
data:
note: The subpackage opensearch-performance-analyzer compilation hardcodes the cloning a specific branch of opensearch-performance-analyzer-rca repository with the vulnerable libraries. This requires upstream changes to opensearch-performance-analyzer-rca repository.

0 comments on commit 52c4fbb

Please sign in to comment.