I read somewhere in the forum that Elastic does not discuss about CVE fixes in the forum. What is the right method to reach-out to elastic? There are two things we need to document for every CVE identified in ES - 1 whether the vulnerability is false positive or impacting 2. which version in the future that can potentially fix this. I am sure this question could have been asked number of times
Security Announcements - Discuss the Elastic Stack is where security announcements are made here.
Product Security at Elastic | Elastic gives some more information about this.
Thanks david. Is the information in here accurate? Here they have mentioned a email Id to reachout -security@elastic.co. I tried this email regarding a CVE to get a comment on whether its false positive.They redirected me to discuss.elastic.co here. Thats why I am wondering what is the appropriate channel to get details about a CVE (whether its impacting or what release if it is planned)
Is the CVE in question mentioned in one of the security announcements?