https://bugzilla.redhat.com/show_bug.cgi?id=1937440
--- Comment #9 from Mark Cooper mcooper@redhat.com --- Statement:
OpenShift Container Platform (OCP) openshift-logging/elasticsearch6-rhel8 container does contain a vulnerable version of velocity, however the references to the library only occur in the x-pack component which is an enterprise only feature of Elasticsearch - hence it has been marked as wontfix as this time and may be fixed in a future release. Additionally the hive-container only references velocity in the testutils of the code but the code still exists in the container, hence it has been given a Moderate impact.