Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 28 Sep 2022 18:00:32 +0000
From:      bugzilla-noreply@freebsd.org
To:        ports-bugs@FreeBSD.org
Subject:   [Bug 266688] Vulnerability in elasticsearch6 package
Message-ID:  <bug-266688-7788@https.bugs.freebsd.org/bugzilla/>

next in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D266688

            Bug ID: 266688
           Summary: Vulnerability in elasticsearch6 package
           Product: Ports & Packages
           Version: Latest
          Hardware: amd64
                OS: Any
            Status: New
          Severity: Affects Only Me
          Priority: ---
         Component: Individual Port(s)
          Assignee: ports-bugs@FreeBSD.org
          Reporter: cristian.cardoso11@gmail.com

Hi
I'm running on my FreeBSD servers the security system and CVE's tenable/nes=
sus
and on one of my servers I'm using the Graylog4/Elasticsearch6 set, after an
audit scan the tenable pointed out the following packages included in the
elasticsearch package as vulnerable:

 Path              : /usr/local/lib/elasticsearch/lib/log4j-core-2.11.1.jar
  Installed version : 2.11.1
  Fixed version     : 2.12.2

  Path              :
/usr/local/lib/elasticsearch/bin/elasticsearch-sql-cli-6.8.16.jar
  Installed version : 2.11.1
  Fixed version     : 2.12.2

It says that it should have the versions mentioned there installed for the =
fix,
but I searched via pkg search elasticsearch6 and there is no update for this
package

Here's the vulnerability link: https://www.tenable.com/plugins/nessus/155999

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-266688-7788>