Open olukas opened 1 year ago
Jet elasticsearch uses snakeyaml in version 1.33 which includes following vulnerability:
snakeyaml
The same CVE is in jmx_prometheus_javaagent-0.16.1.jar (shaded: org.yaml:snakeyaml:1.29).
jmx_prometheus_javaagent-0.16.1.jar (shaded: org.yaml:snakeyaml:1.29)
There is no fix possible in 4.5.4 - all versions contain at least one high prio vunerability, no fix available.
Jet elasticsearch uses
snakeyaml
in version 1.33 which includes following vulnerability:The same CVE is in
jmx_prometheus_javaagent-0.16.1.jar (shaded: org.yaml:snakeyaml:1.29)
.