I Geeting some vulnerability issue in opensearchproject/opensearch:2.8.0 docker Image

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser):
CVE-2023-24540

CVE-2023-24538

CVE-2023-23914

CVE-2022-37434

CVE-2022-32221

CVE-2022-32207

CVE-2022-23806

CVE-2022-1996

Describe the issue:

Configuration:

Relevant Logs or Screenshots:

@davelago @peternied @scrawfor - can you take a look at this? thank you

Thanks for the report, @bhanu1. We are looking into each one and will report back with our findings.

1 Like

Hello,

Thank you for your message about the CVEs reported in OpenSearch version 2.8.0.

The following CVEs have been addressed by including updated versions of the relevant libraries and any necessary fixes in the existing 2.8.0 Docker image:

CVE-2023-24540
CVE-2023-24538
CVE-2023-23914
CVE-2022-37434
CVE-2022-32221
CVE-2022-32207
CVE-2022-23806
CVE-2022-1996

1 Like