# Do I need to upgrade?. Kibana 8.17.3 Security Update (ESA-2025-06)

**URL:** https://discuss.elastic.co/t/do-i-need-to-upgrade-kibana-8-17-3-security-update-esa-2025-06/375756
**Category:** Elasticsearch
**Tags:** elastic-stack-monitoring, elastic-stack-security, elastic-stack-alerting
**Created:** [March 12, 2025, 4:21am UTC](https://discuss.elastic.co/t/do-i-need-to-upgrade-kibana-8-17-3-security-update-esa-2025-06/375756 "2025-03-12T04:21:36Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [March 12, 2025, 4:21am UTC](https://discuss.elastic.co/t/do-i-need-to-upgrade-kibana-8-17-3-security-update-esa-2025-06/375756/1 "2025-03-12T04:21:36Z")

</div>

Hi Elastic Team Member, @ikakavas,

I have read the information from Ikakavas, I am very concerned about my system. But I also want to ask you some questions. Please help me answer my questions.

- I am using ELK cluster version 7.9.0, So when upgrading, do I need to follow the roadmap (From 7.9.0 to 7.17.x and From 7.17.x to 8.x?)

- Before upgrading, what is the most important data I need to backup?

- If my internal version 7.9.0 is stable and does not have any serious security holes. Then follow the method you suggested " Set xpack.integration\_assistant.enabled: false in Kibana's configuration. "

Hope to receive feedback from the Team soon.

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [March 12, 2025, 5:58am UTC](https://discuss.elastic.co/t/do-i-need-to-upgrade-kibana-8-17-3-security-update-esa-2025-06/375756/2 "2025-03-12T05:58:53Z")

</div>

> [@Kibana 8.17.3 / 8.16.6 Security Update (ESA-2025-06)](https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441):
>
> Kibana arbitrary code execution via prototype pollution (ESA-2025-06) Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions \>= 8.15.0 and \< 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only exploitable by users that have roles that contain all the following privileges: fleet-all, integrations-all, actions:execute-advanced-connectors This is…

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [March 12, 2025, 7:30am UTC](https://discuss.elastic.co/t/do-i-need-to-upgrade-kibana-8-17-3-security-update-esa-2025-06/375756/3 "2025-03-12T07:30:50Z")

</div>

I found out that kibana version 7.9.0 is not affected.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [March 12, 2025, 2:34pm UTC](https://discuss.elastic.co/t/do-i-need-to-upgrade-kibana-8-17-3-security-update-esa-2025-06/375756/4 "2025-03-12T14:34:20Z")

</div>

Hi @Nghia_D_ng

> [@Nghia\_D\_ng](#):
>
> I am using ELK cluster version 7.9.0, So when upgrading, do I need to follow the roadmap (From 7.9.0 to 7.17.x and From 7.17.x to 8.x?)

Yes if you want to use your existing cluster you must migrate to 7.17.x before migrating to 8.x

Once you get to 7.17.x you will want to run the Upgrade Assistant and fix all the critical issues at the very least

> **[Upgrade Assistant | Kibana Guide \[7.17\] | Elastic](https://www.elastic.co/guide/en/kibana/7.17/upgrade-assistant.html)**
>
> Kibana provides you with several options to share \*Discover\* saved searches, dashboards, \*Visualize Library\* visualizations, and \*Canvas\* workpads with others, or on a website.

> [@Nghia\_D\_ng](#):
>
> Before upgrading, what is the most important data I need to backup?

I mean this genuinely, if your data is important you should snapshot all of it... including the system indices...

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [March 13, 2025, 1:31am UTC](https://discuss.elastic.co/t/do-i-need-to-upgrade-kibana-8-17-3-security-update-esa-2025-06/375756/5 "2025-03-13T01:31:49Z")

</div>

Sorry @stephenb ,  
I want to know if ELK version 7.9.0 is affected by this ESA-2025-06 bug?

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [March 13, 2025, 3:54am UTC](https://discuss.elastic.co/t/do-i-need-to-upgrade-kibana-8-17-3-security-update-esa-2025-06/375756/6 "2025-03-13T03:54:59Z")

</div>

I can not interpret these announcements for you as there is a clear statement of Affected Versions in [Kibana 8.17.3 Security Update (ESA-2025-06)](https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441) announcement, you should look at that.

Version 7.9.0 is VERY VERY old you should check what CVEs exist for that version. Our normal advice would be to upgrade as a matter of urgency.
