Hello!
Please, there is a security issue on Kibana (Kibana 8.14.2 / 7.17.23 Security Update (ESA-2024-22) - Security Announcements - Discuss the Elastic Stack ) and, since Opensearch-Dashboards is derived on Kibana 7.10.2, i want to know if this vulnerability applies to Opensearch version 2.11.1.
Thanks in advance!
Gabriel.
pablo
August 21, 2024, 12:59pm
2
@gferrette According to the provided link the ESA-2024-22 vulnerability affects Kibana ML module and ML indices.
The Kibana ML module is a paid part of the X-Pack. As far as I’m aware OpenSearch Dashboard’s ML plugin is not related to Kibana’s and it was introduced in version 1.3.0
# OpenSearch and Dashboards 1.3.0 Release Notes
## Release Highlights
### OpenSearch Ml Commons
* The new ML Commons plugin empowers users to train and apply machine learning models as a part of the OpenSearch 1.3.0 release.
## Release Details
OpenSearch and OpenSearch Dashboards 1.3.0 includes the following features, enhancements, bug fixes, infrastructure, documentation, maintenance, and refactoring updates.
OpenSearch [Release Notes](https://github.com/opensearch-project/OpenSearch/blob/main/release-notes/opensearch.release-notes-1.3.0.md).
OpenSearch Dashboards [Release Notes](https://github.com/opensearch-project/OpenSearch-Dashboards/blob/main/release-notes/opensearch-dashboards.release-notes-1.3.0.md).
## FEATURES
### OpenSearch Anomaly Detection
* Adding Model Type Validation to Validate API ("non-blocker") ([#384](https://github.com/opensearch-project/anomaly-detection/pull/384))
This file has been truncated. show original
1 Like