/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-f36r-qrqf-qwr9

Published

Last updated

https://images.chainguard.dev/security/CGA-f36r-qrqf-qwr9
Package

elasticsearch-7

Repository

Chainguard

Latest Update
Fixed
Fixed Version

7.17.24-r0

Aliases
  • CVE-2024-7254
  • GHSA-735f-pc8j-v9w8

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-7254

Updates

Status

Fixed

Fixed version

7.17.24-r0

Status

Pending upstream fix

Impact

The protobuf-java dependency is a transitive dependency that is being brought in under vector-tile which is currently at the most recent version (3.1.0). This transitive dependency must be updated by upstream maintainers.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing