Skip to content

Update dependency org.opensearch:opensearch to v2.11.1 [SECURITY]#48

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/maven-org.opensearch-opensearch-vulnerability
Open

Update dependency org.opensearch:opensearch to v2.11.1 [SECURITY]#48
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/maven-org.opensearch-opensearch-vulnerability

Conversation

@renovate
Copy link

@renovate renovate bot commented Dec 1, 2023

This PR contains the following updates:

Package Change Age Confidence
org.opensearch:opensearch (source) 2.11.02.11.1 age confidence

GitHub Vulnerability Alerts

GHSA-6g3j-p5g6-992f

Impact

A flaw was discovered in OpenSearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.

The issue was identified by Elastic Engineering and corresponds to security advisory ESA-2023-14 (CVE-2023-31419).

Mitigation

Versions 1.3.14 and 2.11.1 contain a fix for this issue.

For more information

If you have any questions or comments about this advisory, please contact AWS/Amazon Security via our issue reporting page (https://aws.amazon.com/security/vulnerability-reporting/) or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue.


Release Notes

opensearch-project/OpenSearch (org.opensearch:opensearch)

v2.11.1

Compare Source

2023-11-20 Version 2.11.1 Release Notes
[2.11.1]
Changed
  • Use iterative approach to evaluate Regex.simpleMatch (#​11060)
Fixed
  • [BUG] Disable sort optimization for HALF_FLOAT (#​10999)
  • Adding version condition while adding geoshape doc values to the index, to ensure backward compatibility.(#​11095)
  • Remove shadowJar from lang-painless module publication (#​11369)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from a team as a code owner December 1, 2023 19:24
@codecov
Copy link

codecov bot commented Dec 1, 2023

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 57.77%. Comparing base (8211229) to head (0a10196).
Report is 18 commits behind head on master.

❗ Current head 0a10196 differs from pull request most recent head 191ea3d. Consider uploading reports for the commit 191ea3d to get more accurate results

Additional details and impacted files
@@             Coverage Diff              @@
##             master      #48      +/-   ##
============================================
+ Coverage     47.94%   57.77%   +9.82%     
- Complexity      125      178      +53     
============================================
  Files            36       43       +7     
  Lines           657      817     +160     
  Branches         65       77      +12     
============================================
+ Hits            315      472     +157     
+ Misses          311      310       -1     
- Partials         31       35       +4     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@renovate renovate bot force-pushed the renovate/maven-org.opensearch-opensearch-vulnerability branch 3 times, most recently from e7220e1 to e3db3a4 Compare February 12, 2024 14:14
@renovate renovate bot force-pushed the renovate/maven-org.opensearch-opensearch-vulnerability branch from e3db3a4 to 0a10196 Compare March 18, 2024 09:45
@renovate renovate bot force-pushed the renovate/maven-org.opensearch-opensearch-vulnerability branch 2 times, most recently from b66c757 to 191ea3d Compare May 2, 2024 17:32
@renovate renovate bot force-pushed the renovate/maven-org.opensearch-opensearch-vulnerability branch 2 times, most recently from 1ce0b57 to ce3aaa2 Compare July 10, 2024 08:20
@renovate renovate bot force-pushed the renovate/maven-org.opensearch-opensearch-vulnerability branch from ce3aaa2 to b6e3b2e Compare September 25, 2024 11:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants