# Elastic Cloud on Kubernetes (ECK) 2.8 Security Update

**URL:** <https://discuss.elastic.co/t/elastic-cloud-on-kubernetes-eck-2-8-security-update/343854>\
**Category:** Security Announcements\
**Created:** [September 26, 2023, 9:48am UTC](https://discuss.elastic.co/t/elastic-cloud-on-kubernetes-eck-2-8-security-update/343854 "2023-09-26T09:48:13Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![ismisepaul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ismisepaul/32/102235_2.png) [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)\
**Post date:** [September 26, 2023, 9:48am UTC](https://discuss.elastic.co/t/elastic-cloud-on-kubernetes-eck-2-8-security-update/343854/1 "2023-09-26T09:48:13Z")

</div>

**Elastic Cloud on Kubernetes (ECK) secret token configuration issue (ESA-2023-11)**

Secret token configuration is never applied when using ECK \<2.8 with APM Server \>=8.0.

This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.

**Affected Versions:**  
Elastic Cloud on Kubernetes (ECK) before 2.8 with APM Server after 8.0

**Solutions and Mitigations:**  
Users should upgrade to Elastic Cloud on Kubernetes (ECK) version 2.8 or higher.

CVSSv3: 5.3 (Medium) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N  
CVE ID: CVE-2023-31416
