Back to all use cases
ElasticsearchSoftware vendors

Pinned to the last Apache-2.0 release

A software vendor ships Elasticsearch 7.10.2 inside its on-premises product because it is the last release available under Apache 2.0. Its customers' scanners now flag 7.x CVEs that Elastic fixed only in 8.19 and 9.x.

Challenge

Moving to a later Elasticsearch changes the licence the vendor distributes under; moving to OpenSearch is a product re-platform that takes several releases.

Environment

Elasticsearch 7.10.2 embedded in a customer-installed product, deployed across hundreds of customer sites.

Approach

OSSeva backports security fixes to 7.10.2 so the vendor can ship patched builds in its next maintenance release, and supports the OpenSearch migration in parallel.

What this delivers

Clean scan results for customers now, and a licence-safe path forward.

Go deeper

See every EOL & CVE-patching use case