opensearch-ruby
OpenSearch Ruby is a Ruby client for OpenSearch. You can use the client to execute OpenSearch API commands, and build OpenSearch queries and aggregations using the included OpenSearch DSL.
Activity
- Latest release
- 1y ago
- Total releases
- 18
- Cadence
- ~30 days
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Dec 06, 2021
| Version | Released | |
|---|---|---|
4.0.0.pre.beta.5
pre
| ||
4.0.0.pre.beta.4
pre
| ||
4.0.0.pre.beta.3
pre
| ||
4.0.0.pre.beta.2
pre
| ||
4.0.0.pre.beta.1
pre
| ||
3.4.0
minor
| ||
3.3.0
minor
| ||
3.2.0
minor
| ||
3.1.0
minor
| ||
3.0.1
patch
| ||
3.0.0
major
| ||
2.1.0
minor
|
2.1.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.0.3
patch
|
2.0.3
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
1.0.1
patch
|
1.0.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.0.2
patch
|
2.0.2
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.0.1
patch
1 CVE
CVE-2022-31115
GHSA-977c-63xq-cgw3
Jul 05, 2022
opensearch-ruby 2.x before 2.0.2 vulnerable to unsafe YAML deserialization
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
ImpactA YAML deserialization in opensearch-ruby 2.0.0 can lead to unsafe deserialization using YAML.load if the response is of type YAML. PatchesThe problem has been patched in opensearch-ruby gem version 2.0.2. WorkaroundsNo viable workaround. Please upgrade to 2.0.2 Referenceshttps://github.com/opensearch-project/opensearch-ruby/pull/77 https://staaldraad.github.io/post/2021-01-09-universal-rce-ruby-yaml-load-updated/ For more informationIf you have any questions or comments about this advisory:
Affected versions
2.0.0
2.0.1
Fixed in
2.0.2
References
Updated Feb 22, 2024 · Source: OSV.dev |
2.0.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.0.0
major
1 CVE
CVE-2022-31115
GHSA-977c-63xq-cgw3
Jul 05, 2022
opensearch-ruby 2.x before 2.0.2 vulnerable to unsafe YAML deserialization
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
ImpactA YAML deserialization in opensearch-ruby 2.0.0 can lead to unsafe deserialization using YAML.load if the response is of type YAML. PatchesThe problem has been patched in opensearch-ruby gem version 2.0.2. WorkaroundsNo viable workaround. Please upgrade to 2.0.2 Referenceshttps://github.com/opensearch-project/opensearch-ruby/pull/77 https://staaldraad.github.io/post/2021-01-09-universal-rce-ruby-yaml-load-updated/ For more informationIf you have any questions or comments about this advisory:
Affected versions
2.0.0
2.0.1
Fixed in
2.0.2
References
Updated Feb 22, 2024 · Source: OSV.dev |
2.0.0
major
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
1.0.0
initial
|
1.0.0
initial
Dependencies (12)
+ 4 more
Changelog
|