# Elastic Stack 6.3.0 and 5.6.10 Security Update

**URL:** <https://discuss.elastic.co/t/elastic-stack-6-3-0-and-5-6-10-security-update/135777>\
**Category:** Security Announcements\
**Created:** [June 13, 2018, 6:23pm UTC](https://discuss.elastic.co/t/elastic-stack-6-3-0-and-5-6-10-security-update/135777 "2018-06-13T18:23:18Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![Maurits\_Fennis](https://avatars.discourse-cdn.com/v4/letter/m/59ef9b/32.png) [@Maurits\_Fennis](https://discuss.elastic.co/u/Maurits_Fennis)\
**Post date:** [June 13, 2018, 6:23pm UTC](https://discuss.elastic.co/t/elastic-stack-6-3-0-and-5-6-10-security-update/135777/1 "2018-06-13T18:23:18Z")

</div>

**Elasticsearch Information Exposure Vulnerability (ESA-2018-10)**  
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the \_snapshot API. When the access\_key and security\_key parameters are set using the \_snapshot API they can be exposed as plain text by users able to query the \_snapshot API.

Although it is advised in the 6.X \_snapshot API documentation to define the access\_key and security\_key parameters in the keystore, it is still possible to define them outside of the keystore using the API.

**Affected Versions:** Elasticsearch versions 6.0.0-beta1 to 6.2.4

**Solutions and Mitigations:**  
All users of Elasticsearch should upgrade to version 6.3.0. This update will prevent the \_snapshot API from returning the access\_key and security\_key parameters in plain text.

**CVE ID:** CVE-2018-3826

* * *

**Elasticsearch Information Exposure Vulnerability (ESA-2018-11)**  
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadvertently logged.

**Affected Versions:**  
All versions of Elasticsearch

**Solutions and Mitigations:**  
All users of Elasticsearch should upgrade to version 6.3.0. This update will prevent the repository-azure plugin to expose Azure credentials in Elasticsearch logs.

**CVE ID:** CVE-2018-3827

---

_[View the full topic](https://discuss.elastic.co/t/elastic-stack-6-3-0-and-5-6-10-security-update/135777)._
