# Elastic Stack 5.5.1 and Kibana 4.6.5 security update

**URL:** https://discuss.elastic.co/t/elastic-stack-5-5-1-and-kibana-4-6-5-security-update/94513
**Category:** Security Announcements
**Created:** [July 25, 2017, 4:20pm UTC](https://discuss.elastic.co/t/elastic-stack-5-5-1-and-kibana-4-6-5-security-update/94513 "2017-07-25T16:20:13Z")
**Posts on this page:** 1
**Showing post:** 1

<div class="post-metadata">

### Author: ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)
#### Post date: [July 25, 2017, 4:20pm UTC](https://discuss.elastic.co/t/elastic-stack-5-5-1-and-kibana-4-6-5-security-update/94513/1 "2017-07-25T16:20:13Z")

</div>

**Kibana Node.js security flaw (ESA-2017-14)**

The version of Node.js shipped in all versions of Kibana prior to 5.5.1 contains a Denial of Service flaw in it's HashTable random seed. This flaw could allow a remote attacker to consume resources within Node.js preventing Kibana from servicing requests.

**Affected Versions**  
All versions before 5.5.1 and 4.6.5

**Solutions and Mitigations:**  
Administrators running Kibana in an environment with untrusted users should upgrade to version 5.5.1 or 4.6.5. There is no workaround for this issue, the flaw can be triggered by an unauthenticated anonymous user.

**CVE ID:** CVE-2017-11499

---

_[View the full topic](https://discuss.elastic.co/t/elastic-stack-5-5-1-and-kibana-4-6-5-security-update/94513)._
