Package
elasticsearch-9-config
Component
bc-fips
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The bc-fips 1.0.2.5 vulnerability affects Elasticsearch's plugin-cli tool. Upstream Elasticsearch is working on updating bc-fips from 1.0.2.5 to 2.1.1 to resolve this issue. The fix requires functional changes and is being tracked in draft PR https://github.com/elastic/elasticsearch/pull/132817. Once this PR is merged and included in a release, the package can be updated.
Status