[Snyk] Upgrade org.elasticsearch.client:elasticsearch-rest-high-level-client from 7.8.1 to 7.17.24 #863
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade org.elasticsearch.client:elasticsearch-rest-high-level-client from 7.8.1 to 7.17.24.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 52 versions ahead of your current version.
The recommended version was released on a month ago.
Issues fixed by the recommended upgrade:
SNYK-JAVA-ORGELASTICSEARCH-6039899
SNYK-JAVA-ORGELASTICSEARCH-6083305
SNYK-JAVA-ORGYAML-2806360
SNYK-JAVA-ORGYAML-6056527
SNYK-JAVA-ORGELASTICSEARCH-1324572
SNYK-JAVA-ORGELASTICSEARCH-2431020
SNYK-JAVA-ORGELASTICSEARCH-6038562
SNYK-JAVA-ORGELASTICSEARCH-6125580
SNYK-JAVA-ORGELASTICSEARCH-6508260
SNYK-JAVA-ORGELASTICSEARCH-7577201
SNYK-JAVA-ORGELASTICSEARCH-1061930
SNYK-JAVA-ORGELASTICSEARCH-1089258
SNYK-JAVA-ORGYAML-3016891
SNYK-JAVA-ORGELASTICSEARCH-2431238
SNYK-JAVA-ORGYAML-3016888
SNYK-JAVA-COMMONSCODEC-561518
SNYK-JAVA-ORGELASTICSEARCH-1021613
SNYK-JAVA-ORGELASTICSEARCH-1071900
SNYK-JAVA-ORGELASTICSEARCH-1083274
SNYK-JAVA-ORGELASTICSEARCH-1089259
SNYK-JAVA-ORGYAML-3016889
SNYK-JAVA-ORGYAML-3113851
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"org.elasticsearch.client:elasticsearch-rest-high-level-client","from":"7.8.1","to":"7.17.24"}],"env":"prod","hasFixes":true,"isBreakingChange":false,"isMajorUpgrade":false,"issuesToFix":[{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-6039899","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-6039899","priority_score":589,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Uncontrolled Resource Consumption ('Resource Exhaustion')"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-6083305","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-6083305","priority_score":589,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Improper Handling of Exceptional Conditions"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGYAML-2806360","issue_id":"SNYK-JAVA-ORGYAML-2806360","priority_score":589,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Denial of Service (DoS)"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGYAML-6056527","issue_id":"SNYK-JAVA-ORGYAML-6056527","priority_score":589,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Denial of Service (DoS)"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-1324572","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-1324572","priority_score":520,"priority_score_factors":[{"type":"exploit","label":"Unproven","score":11},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"5.9","score":295},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-2431020","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-2431020","priority_score":449,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"4.7","score":235},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Cross-site Scripting (XSS)"},{"exploit_maturity":"mature","id":"SNYK-JAVA-ORGELASTICSEARCH-6038562","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-6038562","priority_score":711,"priority_score_factors":[{"type":"exploit","label":"Functional","score":171},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.5","score":325},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Stack-based Buffer Overflow"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-6125580","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-6125580","priority_score":474,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"5.2","score":260},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Insertion of Sensitive Information into Log File"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-6508260","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-6508260","priority_score":429,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"4.3","score":215},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Uncontrolled Recursion"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-7577201","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-7577201","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Missing Encryption of Sensitive Data"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-1061930","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-1061930","priority_score":440,"priority_score_factors":[{"type":"exploit","label":"Unproven","score":11},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"4.3","score":215},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Information Disclosure"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-1089258","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-1089258","priority_score":429,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"4.3","score":215},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Information Disclosure"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JAVA-ORGYAML-3016891","issue_id":"SNYK-JAVA-ORGYAML-3016891","priority_score":536,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"4.3","score":215},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Stack-based Buffer Overflow"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-2431238","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-2431238","priority_score":369,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"3.1","score":155},{"type":"scoreVersion","label":"v1","score":1}],"severity":"low","title":"Missing Authorization"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JAVA-ORGYAML-3016888","issue_id":"SNYK-JAVA-ORGYAML-3016888","priority_score":506,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"3.7","score":185},{"type":"scoreVersion","label":"v1","score":1}],"severity":"low","title":"Stack-based Buffer Overflow"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-COMMONSCODEC-561518","issue_id":"SNYK-JAVA-COMMONSCODEC-561518","priority_score":399,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"3.7","score":185},{"type":"scoreVersion","label":"v1","score":1}],"severity":"low","title":"Information Exposure"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-1021613","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-1021613","priority_score":369,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"3.1","score":155},{"type":"scoreVersion","label":"v1","score":1}],"severity":"low","title":"Information Exposure"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-1071900","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-1071900","priority_score":309,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"1.9","score":95},{"type":"scoreVersion","label":"v1","score":1}],"severity":"low","title":"Information Disclosure"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-1083274","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-1083274","priority_score":344,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"2.6","score":130},{"type":"scoreVersion","label":"v1","score":1}],"severity":"low","title":"Information Exposure"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGELASTICSEARCH-1089259","issue_id":"SNYK-JAVA-ORGELASTICSEARCH-1089259","priority_score":344,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"2.6","score":130},{"type":"scoreVersion","label":"v1","score":1}],"severity":"low","title":"Information Disclosure"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGYAML-3016889","issue_id":"SNYK-JAVA-ORGYAML-3016889","priority_score":399,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"3.7","score":185},{"type":"scoreVersion","label":"v1","score":1}],"severity":"low","title":"Stack-based Buffer Overflow"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGYAML-3113851","issue_id":"SNYK-JAVA-ORGYAML-3113851","priority_score":399,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"3.7","score":185},{"type":"scoreVersion","label":"v1","score":1}],"severity":"low","title":"Stack-based Buffer Overflow"}],"prId":"c25e0c27-ff9f-4063-ab1e-c27d9193d772","prPublicId":"c25e0c27-ff9f-4063-ab1e-c27d9193d772","packageManager":"maven","priorityScoreList":[589,589,589,589,520,449,711,474,429,559,440,429,536,369,506,399,369,309,344,344,399,399],"projectPublicId":"6f226390-d845-4198-821b-1ab29d3c180d","projectUrl":"https://app.snyk.io/org/dataroma/project/6f226390-d845-4198-821b-1ab29d3c180d?utm_source=github&utm_medium=referral&page=upgrade-pr","prType":"upgrade","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["priorityScore"],"type":"auto","upgrade":["SNYK-JAVA-ORGELASTICSEARCH-6039899","SNYK-JAVA-ORGELASTICSEARCH-6083305","SNYK-JAVA-ORGYAML-2806360","SNYK-JAVA-ORGYAML-6056527","SNYK-JAVA-ORGELASTICSEARCH-1324572","SNYK-JAVA-ORGELASTICSEARCH-2431020","SNYK-JAVA-ORGELASTICSEARCH-6038562","SNYK-JAVA-ORGELASTICSEARCH-6125580","SNYK-JAVA-ORGELASTICSEARCH-6508260","SNYK-JAVA-ORGELASTICSEARCH-7577201","SNYK-JAVA-ORGELASTICSEARCH-1061930","SNYK-JAVA-ORGELASTICSEARCH-1089258","SNYK-JAVA-ORGYAML-3016891","SNYK-JAVA-ORGELASTICSEARCH-2431238","SNYK-JAVA-ORGYAML-3016888","SNYK-JAVA-COMMONSCODEC-561518","SNYK-JAVA-ORGELASTICSEARCH-1021613","SNYK-JAVA-ORGELASTICSEARCH-1071900","SNYK-JAVA-ORGELASTICSEARCH-1083274","SNYK-JAVA-ORGELASTICSEARCH-1089259","SNYK-JAVA-ORGYAML-3016889","SNYK-JAVA-ORGYAML-3113851"],"upgradeInfo":{"versionsDiff":52,"publishedDate":"2024-09-09T10:11:09.000Z"},"vulns":["SNYK-JAVA-ORGELASTICSEARCH-6039899","SNYK-JAVA-ORGELASTICSEARCH-6083305","SNYK-JAVA-ORGYAML-2806360","SNYK-JAVA-ORGYAML-6056527","SNYK-JAVA-ORGELASTICSEARCH-1324572","SNYK-JAVA-ORGELASTICSEARCH-2431020","SNYK-JAVA-ORGELASTICSEARCH-6038562","SNYK-JAVA-ORGELASTICSEARCH-6125580","SNYK-JAVA-ORGELASTICSEARCH-6508260","SNYK-JAVA-ORGELASTICSEARCH-7577201","SNYK-JAVA-ORGELASTICSEARCH-1061930","SNYK-JAVA-ORGELASTICSEARCH-1089258","SNYK-JAVA-ORGYAML-3016891","SNYK-JAVA-ORGELASTICSEARCH-2431238","SNYK-JAVA-ORGYAML-3016888","SNYK-JAVA-COMMONSCODEC-561518","SNYK-JAVA-ORGELASTICSEARCH-1021613","SNYK-JAVA-ORGELASTICSEARCH-1071900","SNYK-JAVA-ORGELASTICSEARCH-1083274","SNYK-JAVA-ORGELASTICSEARCH-1089259","SNYK-JAVA-ORGYAML-3016889","SNYK-JAVA-ORGYAML-3113851"]}'