Trying to determine what needs updated to the ElasticSearch 6.1.2_02 Linux server in order to elimin
Trying to determine what needs updated to the ElasticSearch Linux server in order to eliminate cross site scripting vulnerability. Can you provide information on what we would need beyond v6.12 to eliminate the issue? Looks like Puppet is used, trying to understand if there are other components on the Linux server beyond ES that would need updated like a Web server that is installed with ES. The Linux server is only used to run Oracle ES so anything on it would have been set up by the DPK for ElasticSearch. I thought that perhaps because we still have binaries from