Skip to content

[BUG] OpenSearch 3.1.0 image subject to CVE-2025-48924 #18760

@hasselg

Description

@hasselg

Describe the bug

Automated scanning by Twistlock and Anchore are detecting CVE-2025-48924 embedded in the 3.1.0 image in multiple places--it looks like mostly in included plugins.

I see:

  • /usr/share/opensearch/plugins/opensearch-sql/opensearch-sql-3.1.0.0.jar
  • /usr/share/opensearch/plugins/opensearch-knn/commons-lang-2.6.jar
  • /usr/share/opensearch/plugins/opensearch-ml/commons-lang3-3.10.jar
  • /usr/share/opensearch/plugins/opensearch-security-analytics/commons-lang3-3.14.0.jar
  • /usr/share/opensearch/plugins/opensearch-anomaly-detection/commons-lang3-3.17.0.jar

Related component

No response

To Reproduce

Scan 3.1.0 image.

Expected behavior

No known vulnerabilities.

Additional Details

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions