Upgrade OpenSearch to 1.3.7 to mitigate CVE-2022-42889

XMLWordPrintable

    • 2
    • Severity 3 - Minor
    • 26

      In BSERV-13534 commons-text usages were upgraded in the Bitbucket Webapp to mitigate against CVE-2022-42889 (although Bitbucket WebApp was actually unaffected). The bundled OpenSearch should also be updated to 1.3.7 when it is released. The release date is currently scheduled for 13-Dec-2022: https://opensearch.org/releases.html

      References:

            Assignee:
            Josh Aguilar
            Reporter:
            Ben Humphreys
            Votes:
            5 Vote for this issue
            Watchers:
            18 Start watching this issue

              Created:
              Updated:
              Resolved: