# Elastic Stack 5.4.1 and 5.3.3 Security updates

**URL:** <https://discuss.elastic.co/t/elastic-stack-5-4-1-and-5-3-3-security-updates/87952>\
**Category:** Security Announcements\
**Created:** [June 1, 2017, 4:29pm UTC](https://discuss.elastic.co/t/elastic-stack-5-4-1-and-5-3-3-security-updates/87952 "2017-06-01T16:29:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)\
**Post date:** [June 1, 2017, 4:29pm UTC](https://discuss.elastic.co/t/elastic-stack-5-4-1-and-5-3-3-security-updates/87952/1 "2017-06-01T16:29:34Z")

</div>

**X-Pack 5.4.1 privilege escalation (ESA-2017-06)**

X-Pack 5.4.1 has been released which fixes a privilege escalation bug in the run\_as functionality. This bug prevents transitioning into the specified user specified in a run\_as request. If a role has been created using a template that contains the \_user properties, the behavior of run\_as will be incorrect. Additionally if the run\_as user specified does not exist, the transition will not happen.  
Generally when using the run as functionality a user will transition to a different user. This bug will cause the role query to execute as the user which authenticated to Elasticsearch, not the user specified via run as. This could result in a query returning incorrect or unexpected results.

If you are not using run\_as functionality or the \_user properties you are not affected by this issue.

**Affected versions**  
X-Pack Security 5.0.0 to 5.4.0 is affected by this flaw

**Solution and Mitigations**  
If you are affected by this issue, we suggest you upgrade your Elastic Stack to version 5.4.1  
If you are unable to upgrade, removing use of the {{\_user.username}} placeholder and ensuring the run\_as setting cannot be modified by untrusted users is a valid solution.

**CVE ID:** CVE-2017-8438

* * *

**Kibana 5.4.1 Cross Site Scripting (ESA-2017-07)**

Kibana 5.4.1 has been released which fixes a cross site scripting bug in the Time Series Visual Builder. This bug could allow an attacker to construct a visualization in such a way that when viewed by another Kibana user could leak sensitive information from or perform destructive actions on behalf of the Kibana user.

**Affected versions**  
Kibana 5.4.0 is affected by this flaw

**Solution and Mitigations**  
We strongly advise users to update to Kibana version 5.4.1.  
If you are unable to upgrade at this time, the Time Series Visual Builder can be disabled by adding ‘metrics.enabled: false’ to your kibana.yml configuration file. Note that this will trigger an optimize cycle when you next start Kibana.

**CVE ID:** CVE-2017-8439

* * *

**Kibana 5.4.1 and 5.3.3 Cross Site Scripting (ESA-2017-08)**

Kibana 5.4.1 and 5.3.3 have been released which fix a cross site scripting bug in the Discover page. An attacker who is able to insert arbitrary data into elasticsearch that when viewed by another Kibana user on the Discover page could leak sensitive information from or perform destructive actions on behalf of the Kibana user.

**Affected versions**  
Kibana versions between 5.3.0 and 5.4.0 are affected by this flaw

**Solution and Mitigations**  
We strongly advise users to update to Kibana version 5.4.1 or 5.3.3.

**CVE ID:** CVE-2017-8440

Elastic would like to thank Thomas Gøytil for reporting this issue.

* * *

**X-Pack 5.4.1 and 5.3.3 improper DLS alias enforcement (ESA-2017-09)**

X-Pack 5.4.1 and 5.3.3 have been released with a fix for a bug in the way Document Level Security is applied to index aliases. This bug could allow a user with restricted permissions to view data they should not have access to when performing certain operations against an index alias.

**Affected versions**  
X-Pack Security 5.0.0 to 5.4.0 is affected by this flaw

**Solution and Mitigations**  
If you are affected by this issue, we suggest you upgrade your Elastic Stack to version 5.4.1 or 5.3.3.

If you are unable to upgrade, the shard request cache can be disabled for indices that use aliases. Instructions to disable the request cache can be found [here](https://www.elastic.co/guide/en/elasticsearch/reference/5.4/shard-request-cache.html#_enabling_and_disabling_caching)

**CVE ID:** CVE-2017-8441

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/elastic-stack-5-4-1-and-5-3-3-security-updates/87952/2 "2017-07-06T13:46:12Z")

</div>


