Skip to content

[Cycode] Fix for vulnerable manifest file dependency - org.elasticsearch:elasticsearch updated to version 7.17.8 - #48

Open
cycode-security[bot] wants to merge 1 commit into
logziofrom
cycode-fix-suggestion-manifest-dependency-update-a6e61897-b8df-4e97-92b9-8f8de4872a74
Open

cycode-security[bot] wants to merge 1 commit into
logziofrom
cycode-fix-suggestion-manifest-dependency-update-a6e61897-b8df-4e97-92b9-8f8de4872a74

Conversation

@cycode-security

Copy link
Copy Markdown

Cycode Vulnerable Dependencies Update

This pull request updates the following manifest file:

File Path Number of packages to update
jest-droid/pom.xml 1

📂 jest-droid/pom.xml

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
org.elasticsearch:elasticsearch 6.8.3 7.17.8

Important

This pull request updates the major version for one or more packages. Make sure changes are tested before merging.

Comment thread jest-droid/pom.xml
<dependency>
<groupId>org.elasticsearch</groupId>
<artifactId>elasticsearch</artifactId>
<version>7.17.8</version>

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❗Cycode: Security vulnerability found in newly introduced dependency.

Risk Score 77 (HIGH)
Severity High
Issue Elasticsearch vulnerable to Uncontrolled Resource Consumption: CVE-2023-31418
Ecosystem Maven
Dependency org.elasticsearch:elasticsearch
Dependency Paths org.elasticsearch elasticsearch 7.17.8
Direct Dependency Yes
Development Dependency No
Upgrade 7.17.13

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.

Description

Detects when new vulnerabilities affect your dependencies.

Tell us how you wish to proceed using one of the following commands:

Tag Short Description
#cycode_ignore_manifest_here <reason> Applies to this manifest in this request only
#cycode_vulnerable_package_fix_this_violation Fix this violation via a commit to this branch
#cycode_ignore_package_here <reason> Applies to this manifest for this package in this request only

⚠️ When commenting on Github, you may need to refresh the page to see the latest updates.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants