Please read this before reporting a bug:
http://wiki.archlinux.org/index.php/Reporting_Bug_Guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Thursday, 18 March 2021, 12:15 GMT
|
DetailsSummary The package elasticsearch is vulnerable to information disclosure via CVE-2021-22132.
Guidance Upgrading elasticsearch to version 7.10.2 fixes the issue.
References
https://security.archlinux.org/AVG-1455 |
This task depends upon
Looking at the CVE details, this bug is fixed in elasticsearch 7.10.2, which is still under the Apache 2.0 license.