Replace squel package #94199
Labels
bug
Fixes for quality problems that affect the customer experience
Feature:Canvas
impact:high
Addressing this issue will have a high level of impact on the quality/strength of our product.
loe:medium
Medium Level of Effort
Team:Presentation
Presentation Team for Dashboard, Input Controls, and Canvas
The squel package is no longer maintained. It was last updated almost 3 years ago and is currently vulnerable to SQL Injection.
This is currently used by Canvas to create ES SQL query strings:
kibana/x-pack/plugins/canvas/canvas_plugin_src/functions/server/esdocs.ts
Line 8 in 931b54f
This dependency should be removed from Kibana.
CC @elastic/kibana-security
The text was updated successfully, but these errors were encountered: