opensearch-dashboards-2
Chainguard
Status
Impact
To remediate this CVE would require a bump of two major versions from v4.x.x to v6.0.2 where breaking changes related to handling of sparse arrays (v5.0.0) and passing of URL object values (v6.0.0) need to be addressed by upstream maintainers. There is a PR open upstream regarding this CVE: https://github.com/opensearch-project/OpenSearch-Dashboards/issues/9375