SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 71137: SAS® Viya® 3.5 contains a file that is affected by Elasticsearch vulnerabilities CVE-2024-22243 and CVE-2024-38828

DetailsHotfixAboutRate It

Severity: High

Description: SAS Viya 3.5 contains a file that is affected by the CVE-2024-22243 and CVE-2024-38828 vulnerabilities. 

Potential Impact: Information about the potential impact is located at CVE-2024-22243 and CVE-2024-38828

Circumvention

Complete the following steps to circumvent these vulnerabilities and avoid negative impact to the SAS system:

  1. Move or remove the /opt/sas/viya/home/libexec/elasticsearch-secure/plugins/opensearch-sql directory.
  2. Run the following to restart OpenSearch: sudo systemctl restart sas-viya-svi-elasticsearch-default
  3. Verify that the plug-in is no longer included in the list of loaded plug-ins on start-up by checking the OpenSearch log file: /var/log/sas/viya/svi-elasticsearch/sas-opensearch.log

No SAS hot fix is required for remediation. The instructions above resolve the vulnerabilities without negative impact to the SAS system.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Viya 3.xMicrosoft® Windows® for x643.5Viya 3.5
Linux for x643.5Viya 3.5
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.