elasticsearch-9
Chainguard
Status
Impact
The bc-fips 1.0.2.5 vulnerability affects Elasticsearch's plugin-cli tool. Upstream Elasticsearch is working on updating bc-fips from 1.0.2.5 to 2.1.1 to resolve this issue. The fix requires functional changes and is being tracked in draft PR https://github.com/elastic/elasticsearch/pull/132817. Once this PR is merged and included in a release, the package can be updated.
Status