Upgrade OpenSearch to 1.3.7 to mitigate CVE-2022-42889

XMLWordPrintable

    • 2
    • Severity 3 - Minor
    • 26

      In BSERV-13534 commons-text usages were upgraded in the Bitbucket Webapp to mitigate against CVE-2022-42889 (although Bitbucket WebApp was actually unaffected). The bundled OpenSearch should also be updated to 1.3.7 when it is released. The release date is currently scheduled for 13-Dec-2022: https://opensearch.org/releases.html

      References:

              Assignee:
              Josh Aguilar
              Reporter:
              Ben Humphreys
              Votes:
              5 Vote for this issue
              Watchers:
              18 Start watching this issue

                Created:
                Updated:
                Resolved: