Dec 23, 2022
Improved
OpenSearch and OpenSearch Dashboards have been updated to version 1.3.7. Along with various enhancements, this release includes critical fixes for CVE-2022-38900, where a vulnerability was found in decode-URI-component 0.2.0 and affected improper input validation resulting in DoS. CVE-2022-42889, where a flaw was found in Apache Commons Text packages version 1.5 through 1.9, allowing properties to be dynamically evaluated and expanded. For more information, see OpenSearch release notes.