Package
logstash-8.19-with-output-opensearch
Component
concurrent-ruby
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable version of concurrent-ruby ships in the package's vendored Ruby gem bundle. The patched release, concurrent-ruby 1.3.7, cannot be adopted because the upstream core gemspec constrains concurrent-ruby to "~> 1, < 1.1.10", and pinning any newer version fails dependency resolution at build time; the bundled 1.1.9 is the newest release the constraint permits. The constraint is present in the latest upstream releases of this version stream and remains in place on the upstream development branch (tracked upstream in elastic/logstash#13956). This will be remediated once upstream relaxes the constraint and publishes a release that bundles concurrent-ruby 1.3.7 or later.
Status