/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-f76p-37jc-4857

Published

Last updated

https://images.chainguard.dev/security/CGA-f76p-37jc-4857
Package

camunda-zeebe-8.7

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2024-52980
  • GHSA-ghfh-p92w-j4mg

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-52980

Updates

Status

Pending upstream fix

Impact

Upstream maintainers need to address CVE-2024-52980, as the substantial code changes between Elasticsearch versions 7.17.28 and 8.15.1, combined with Camunda Zeebe's direct use of Elasticsearch internals, have caused build failures during attempted upgrades.

Status

Pending upstream fix

Impact

Remediation requires upgrading the Elasticsearch Java client from 8.13.4 to 8.15+, which introduces breaking API changes (RangeQuery.Builder.field() method removal) that require substantial code changes. The fix exists in https://github.com/camunda/camunda/pull/29167 but contains branching functional changes and fails to build when applied to 8.7.6. Upstream maintainers will need to release a new minor version with the Elasticsearch client compatibility fixes to remediate this issue.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing