We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
A couple of CVEs are present in this chart which require some component upgrades.
CVE-2024-21538 -> cross spawn to be upgraded to 7.0.5 axios has to be upgraded to 1.6.1 as part of CVE-2023-45857.
Is there any update or timeline when these issues will be remediated?
Thanks in advance!
The text was updated successfully, but these errors were encountered:
[Triage] Hey @shashank-shridhar thanks for creating the issue, is there a chance you can PR the fix ? @TheAlgo @DandyDeveloper @peterzhuamazon
Sorry, something went wrong.
I do notice GHSA-3xgq-45jj-v275 in other repos as well. As for https://nvd.nist.gov/vuln/detail/CVE-2023-45857 might need to take a look.
Thanks.
Similar to #635, the related core and plugins are doing the updates.
We will update the to use the next 2.19.0 release in OpenSearch / OpenSearch-Dashboards.
No branches or pull requests
A couple of CVEs are present in this chart which require some component upgrades.
CVE-2024-21538 -> cross spawn to be upgraded to 7.0.5
axios has to be upgraded to 1.6.1 as part of CVE-2023-45857.
Is there any update or timeline when these issues will be remediated?
Thanks in advance!
The text was updated successfully, but these errors were encountered: