Package
commercial-elasticsearch-8.19
Component
jakarta.mail
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
This vulnerability exists in jakarta.mail 1.6.3 which is bundled inside the upstream elasticsearch distribution at /usr/share/elasticsearch/modules/x-pack-security/jakarta.mail-1.6.3.jar. As a pre-built binary artifact, the embedded dependencies cannot be updated independently. This requires a new upstream release of elasticsearch with jakarta.mail >= 1.6.8 (fixed in 1.6.8; also fixed in org.eclipse.angus:smtp >= 2.0.4 / com.sun.mail:jakarta.mail >= 2.0.2). See: https://github.com/advisories/GHSA-9342-92gg-6v29
Status
Status
Fixed version
8.19.14-r0Status
Impact
Upstream vendor must apply fix
Status