# Elastic Cloud Enterprise (ECE) 2.13.3, 3.3.0 Security Update

**URL:** <https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-2-13-3-3-3-0-security-update/338650>\
**Category:** Security Announcements\
**Created:** [July 18, 2023, 9:57am UTC](https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-2-13-3-3-3-0-security-update/338650 "2023-07-18T09:57:18Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![ismisepaul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ismisepaul/32/102235_2.png) [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)\
**Post date:** [July 18, 2023, 9:57am UTC](https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-2-13-3-3-3-0-security-update/338650/1 "2023-07-18T09:57:18Z")

</div>

ECE Denial of Service (DoS) issue (ESA-2023-09)

A denial of service vulnerability was discovered in ECE that could lead to the ECE Admin API server becoming unavailable if a maliciously crafted JWT is supplied. This is due to the use of a transitive dependency [json-smart](https://nvd.nist.gov/vuln/detail/CVE-2023-1370) which parses nested arrays in an unsafe way. Deployments that run on ECE are unaffected.

Affected Versions:

ECE Versions before 2.13.3 and before 3.3.0

Solutions and Mitigations:

The dependency has been updated which resolves the issue in versions 2.13.3 and 3.3.0

CVSSv3: 7.5 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE ID: CVE-2023-1370

---

_[View the full topic](https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-2-13-3-3-3-0-security-update/338650)._
