CVE-2022-23712: A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.
Ah, we already have a fixed version. Please cleanup.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=13a3013b70de6756ab2a48919220af0a0de38394 commit 13a3013b70de6756ab2a48919220af0a0de38394 Author: Joonas Niilola <juippis@gentoo.org> AuthorDate: 2022-06-21 07:17:03 +0000 Commit: Joonas Niilola <juippis@gentoo.org> CommitDate: 2022-06-21 07:25:43 +0000 app-misc/elasticsearch: drop 6.8.23, 7.17.3 Bug: https://bugs.gentoo.org/850148 Signed-off-by: Joonas Niilola <juippis@gentoo.org> app-misc/elasticsearch/Manifest | 3 - app-misc/elasticsearch/elasticsearch-6.8.23.ebuild | 90 ---------------------- app-misc/elasticsearch/elasticsearch-7.17.3.ebuild | 83 -------------------- app-misc/elasticsearch/metadata.xml | 3 - 4 files changed, 179 deletions(-)
Thanks, all done!