I read somewhere in the forum that Elastic does not discuss about CVE fixes in the forum. What is the right method to reach-out to elastic? There are two things we need to document for every CVE identified in ES - 1 whether the vulnerability is false positive or impacting 2. which version in the future that can potentially fix this. I am sure this question could have been asked number of times
Security Announcements - Discuss the Elastic Stack is where security announcements are made here.
Product Security at Elastic | Elastic gives some more information about this.
Thanks david. Is the information in here accurate? Here they have mentioned a email Id to reachout -security@elastic.co. I tried this email regarding a CVE to get a comment on whether its false positive.They redirected me to discuss.elastic.co here. Thats why I am wondering what is the appropriate channel to get details about a CVE (whether its impacting or what release if it is planned)
Is the CVE in question mentioned in one of the security announcements?
Hello David, Thanks for responding. I wanted to know about this - sonatype-2022-6438. I am not sure of the equivalent CVE. It was reported to me with the above scanner with message - "azure-json 1.2.0 embeds (shades) jackson-core 2.13.5, which is vulnerable to a Denial of Service attack via unrestricted numeric deserialization." I am looking to find whether which version of es this would be likely fixed. Please feel free to remove this if it violates the policy
I can't comment on the security implications here but I think your scanner is faulty as I can find nothing to indicate that Elasticsearch actually uses that version of jackson-core.
I can find azure-json 1.2.0 is getting shipped. Azure-jsone seem to shade jackson-core 2.13.5
Hmm I see. I think you need to try again with security@elastic.co.