opensearch-2
Chainguard
Status
Impact
The reactor-netty-http @ 1.1.23 vulnerability cannot be fixed in OpenSearch 2.19.1 due to complex functional changes required for the security update. OpenSearch upstream attempted a backport to the 2.x branch but it failed. OpenSearch 3.x is slated to include reactor-netty 1.2.5+ which contains the precursors for the fix. References: Failed backport: https://github.com/opensearch-project/OpenSearch/pull/17377#issuecomment-2777169427, https://github.com/opensearch-project/OpenSearch/commit/eb905709242eff2f95807f74981590251dad85e7, https://github.com/opensearch-project/OpenSearch/commit/c060f92b6d5ee4fb6f6c92aa1912d34e6d5dfe91, https://github.com/opensearch-project/OpenSearch/commit/fa4595cf853f2f55b6a4ffc9f653330f6a25688d
Status
Status
Fixed version
2.19.1-r6Status