Package
logstash-fips-9.4-iamguarded-compat
Component
bcpkix-jdk18on
Latest update
Fixed version
9.4.4-r0
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
9.4.4-r0Status
Impact
This vulnerability exists in bcpkix-jdk18on 1.83 bundled inside JRuby's own standard library at /vendor/jruby/lib/ruby/stdlib/org/bouncycastle/. This is a frozen copy shipped with the JRuby distribution itself, separate from the standalone jruby-openssl gem. As an embedded part of the pre-built JRuby distribution, this bundled jar cannot be updated independently via Gemfile pins or other dependency management. Resolution requires an upstream JRuby release that bundles bcpkix-jdk18on 1.84 or later in its stdlib.
Status