logstash-jre-bcfips
Chainguard
5.3
CVSS V3
Status
Impact
Logstash bundles an upstream version of jruby which embeds a version of bouncycastle at lib/ruby/stdlib/org/bouncycastle with the jruby-openssl. Upstream jruby-openssl should update the bouncycastle version that fix this vulnerability as it updates its default gems on some next release.
Status
Status
Fixed version
8.13.4-r0Status
Impact
Logstash bundles an upstream version of jruby which embeds a version of bouncycastle at lib/ruby/stdlib/org/bouncycastle with the jruby-openssl. Upstream jruby-openssl should update the bouncycastle version that fix this vulnerability as it updates its default gems on some next release.
Status