Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions jest-droid/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -79,6 +79,7 @@
<dependency>
<groupId>org.elasticsearch</groupId>
<artifactId>elasticsearch</artifactId>
<version>7.17.8</version>

Check failure on line 82 in jest-droid/pom.xml

View check run for this annotation

Cycode Security / Cycode: Vulnerable Dependencies

jest-droid/pom.xml#L82

Vulnerability found in dependency found

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❗Cycode: Security vulnerability found in newly introduced dependency.

Risk Score 77 (HIGH)
Severity High
Issue Elasticsearch vulnerable to Uncontrolled Resource Consumption: CVE-2023-31418
Ecosystem Maven
Dependency org.elasticsearch:elasticsearch
Dependency Paths org.elasticsearch elasticsearch 7.17.8
Direct Dependency Yes
Development Dependency No
Upgrade 7.17.13

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.

Description

Detects when new vulnerabilities affect your dependencies.

Tell us how you wish to proceed using one of the following commands:

Tag Short Description
#cycode_ignore_manifest_here <reason> Applies to this manifest in this request only
#cycode_vulnerable_package_fix_this_violation Fix this violation via a commit to this branch
#cycode_ignore_package_here <reason> Applies to this manifest for this package in this request only

⚠️ When commenting on Github, you may need to refresh the page to see the latest updates.

</dependency>

<!--Logging -->
Expand Down
Loading