Please read this before reporting a bug:
http://wiki.archlinux.org/index.php/Reporting_Bug_Guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Tuesday, 23 March 2021, 18:49 GMT
|
DetailsSummary The package elasticsearch is vulnerable to information disclosure via CVE-2021-22137, CVE-2021-22135 and CVE-2021-22134.
Guidance Upgrading Elasticsearch to version 7.12.0 fixes the issues.
References
https://security.archlinux.org/AVG-1638 |
This task depends upon
Looking at the CVE details, all three of these CVEs are pertaining to Document and Field Level Security, which is only present in the non-OSS release.
If FS#70388 is fixed so that Arch Linux distributes the OSS release of 7.10.x, then these CVEs would not be a problem.
Another (denial of service) security issue (CVE-2021-22144) has been found in Elasticsearch before version 7.3.13: https://discuss.elastic.co/t/elasticsearch-7-13-3-and-6-8-17-security-update/278100