# Elastic Stack 8.7.0, 7.17.10 Security Updates

**URL:** <https://discuss.elastic.co/t/elastic-stack-8-7-0-7-17-10-security-updates/332327>\
**Category:** Security Announcements\
**Created:** [May 2, 2023, 4:01pm UTC](https://discuss.elastic.co/t/elastic-stack-8-7-0-7-17-10-security-updates/332327 "2023-05-02T16:01:34Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bryan\_Garcia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bryan_garcia/32/148179_2.png) [@Bryan\_Garcia](https://discuss.elastic.co/u/Bryan_Garcia)\
**Post date:** [May 2, 2023, 4:01pm UTC](https://discuss.elastic.co/t/elastic-stack-8-7-0-7-17-10-security-updates/332327/1 "2023-05-02T16:01:34Z")

</div>

**Filebeat Information Exposure (ESA-2023-04)**

A flaw was discovered in the Filebeat httpjson input that allows the http request Authorization or Proxy-Authorization header contents to be leaked in the logs when debug logging is enabled.

**Affected Versions:**

All filebeat versions through 7.17.9 and 8.6.2

**Solutions and Mitigations:**

The issue is resolved in versions 8.7.0, and 7.17.10

**CVSSv3:** 5.5(Medium) - AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

**CVE ID:** CVE-2023-31413

* * *

**Kibana Cross-Site Scripting (ESA-2023-05)**

A flaw ([CVE-2023-26486](https://github.com/advisories/GHSA-4vq7-882g-wcg4)) was discovered in one of Kibana’s dependencies, which could allow arbitrary JavaScript to be executed in a victim’s browser via a maliciously crafted custom visualization in Kibana.

**Affected Versions:**

Kibana versions 7.9.0 to 7.17.9 and Kibana versions 8.0.0 to 8.6.2

**Solutions and Mitigations:**

The issue is resolved in versions 7.17.10 and 8.7.0

If you are unable to upgrade and are on Kibana versions \>= 8.3.0, the XSS can be mitigated by setting `csp.disableUnsafeEval: true` in your kibana.yml file. Note that this setting is in technical preview until Kibana 8.7.0, after which it is enabled by default.

**CVSSv3:** 6.1(Medium) - AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

**CVE ID:** CVE-2023-26486

* * *

**Kibana Cross-Site Scripting (ESA-2023-06)**

A flaw (CVE-2023-26487) was discovered in one of Kibana’s dependencies, which could allow arbitrary JavaScript to be executed in a victim’s browser via a maliciously crafted custom visualization in Kibana.

**Affected Versions:**  
Kibana versions 7.17.4 to 7.17.9 and Kibana versions 8.2.0 to 8.6.2

**Solutions and Mitigations:**  
The issue is resolved in versions 7.17.10 and 8.7.0

If you are unable to upgrade and are on Kibana versions \>= 8.3.0, the XSS can be mitigated by setting `csp.disableUnsafeEval: true` in your kibana.yml file. Note that this setting is in technical preview until Kibana 8.7.0, after which it is enabled by default.

**CVSSv3:** 6.1(Medium) - AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N  
**CVE ID:** CVE-2023-26487

* * *
