Security

Voltar para Security Alert

Elastic Stack and Liferay Enterprise Search Security Advisory: Security Statement for Oracle July Critical Patch Update CVE-2022-21540, CVE-2022-21541, CVE-2022-21549, CVE-2022-25647, CVE-2022-34169

This advisory was prepared to reflect on Elastic's security statement issued for the Oracle July Critical Patch Update recently.

Elastic's Statement

Oracle released their July Critical Patch Update for Java SE which contains 5 CVEs. Elastic has analyzed the flaws described by these CVEs and the information publicly available and determined that these do not introduce a vulnerability for any of our products or services. Out of abundance of caution, the JDK version that is bundled with our products has been updated to a non affected version with our latest releases.

Elasticsearch

Given the CVE description, the changes in the JDK source code and the information publicly available we believe that Elasticsearch is not affected by any of the aforementioned flaws.
Elasticsearch bundles a JDK with all download artifacts ( archives, RPM/DEB packages, Docker images ).

Elasticsearch has already shipped with an unaffected version of JDK, 18.0.2, since version 8.3.3. Versions 8.4.0 and 7.17.6 that are released on 2022-08-24 also bundle JDK 18.0.2.

Additional Information

Reference the information here for the detailed Elasticsearch compatibility including the compatible Java versions for your Liferay DXP-Elasticsearch stack.

Source

https://discuss.elastic.co/t/elastic-stack-8-4-0-7-17-6-security-statement/312823


Elastic, Elasticsearch, and X-Pack are trademarks of Elasticsearch BV, registered in the U.S. and in other countries.

On this page