# Elastic Stack 7.4.1 security update

**URL:** <https://discuss.elastic.co/t/elastic-stack-7-4-1-security-update/204909>\
**Category:** Security Announcements\
**Created:** [October 23, 2019, 4:07pm UTC](https://discuss.elastic.co/t/elastic-stack-7-4-1-security-update/204909 "2019-10-23T16:07:14Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)\
**Post date:** [October 23, 2019, 4:07pm UTC](https://discuss.elastic.co/t/elastic-stack-7-4-1-security-update/204909/1 "2019-10-23T16:07:14Z")

</div>

**Logstash Beats input denial of service flaw (ESA-2019-14)**  
A denial of service flaw was found in the Logstash beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could send a specially crafted network packet that would cause Logstash to stop responding.

If you are not using the Beats input plugin with Logstash you are not vulnerable to this issue.

Thanks to Dennis Detering, IT security consultant at Spike Reply for reporting this issue.

**Affected Versions**  
Logstash versions before 7.4.1 and 6.8.4

**Solutions and Mitigations:**  
Users should upgrade to Logstash version 7.4.1 or 6.8.4.

**CVSSv3:** 7.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H  
**CVE ID:** CVE-2019-7620

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:30am UTC](https://discuss.elastic.co/t/elastic-stack-7-4-1-security-update/204909/2 "2022-11-04T07:30:39Z")

</div>


