# Elasticsearch 8.15.2: OpenJDK CVEs

**URL:** https://discuss.elastic.co/t/elasticsearch-8-15-2-openjdk-cves/377335
**Category:** Elasticsearch
**Tags:** elastic-stack-security
**Created:** [April 21, 2025, 9:36am UTC](https://discuss.elastic.co/t/elasticsearch-8-15-2-openjdk-cves/377335 "2025-04-21T09:36:03Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![debbbuu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debbbuu/32/144975_2.png) [@debbbuu](https://discuss.elastic.co/u/debbbuu)
#### Post date: [April 21, 2025, 9:36am UTC](https://discuss.elastic.co/t/elasticsearch-8-15-2-openjdk-cves/377335/1 "2025-04-21T09:36:03Z")

</div>

Hi,

As part of the vulnerability assessment (VA) scan on our ELK servers, we identified that the bundled OpenJDK version is affected by multiple vulnerabilities. We are using a self-managed cluster. We did upgrade the ELK stack from version 8.13.2 to 8.15.2, but the OpenJDK vulnerabilities still remain unresolved.

**Current Elasticsearch Version:** 8.15.2  
**Path:** /usr/share/elasticsearch/jdk/  
**Installed Bundled JDK Version:** 22.0.1

The reported CVE IDs are:

- CVE-2024-21131
- CVE-2024-21138
- CVE-2024-21140
- CVE-2024-21144
- CVE-2024-21145
- CVE-2024-21147

Our security team has suggested upgrading to an OpenJDK version greater than 22.0.1.

Is it possible to manually upgrade the bundled OpenJDK version? If so, how can this be done? If not, what is the recommended solution to resolve these vulnerabilities?

Alternatively, do we need to upgrade the entire ELK stack again, as we did previously, to a newer version? _(This approach isn’t ideal, as it would require manual intervention each time a new VA is discovered.)_

I've already gone through **[Java (JVM) version](https://www.elastic.co/docs/deploy-manage/deploy/self-managed/installing-elasticsearch#jvm-version)**, but didn't helped.

I would appreciate any guidance on this matter.

Thanks.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [April 21, 2025, 1:47pm UTC](https://discuss.elastic.co/t/elasticsearch-8-15-2-openjdk-cves/377335/2 "2025-04-21T13:47:32Z")

</div>

Duplicate

> [@Issue with OpenJDK Vulnerabilities (CVE-2024) in Elasticsearch 8.15.2](https://discuss.elastic.co/t/issue-with-openjdk-vulnerabilities-cve-2024-in-elasticsearch-8-15-2/377328/1):
>
> Hi, As part of the vulnerability assessment (VA) scan on our ELK servers, we identified that the OpenJDK version is affected by multiple vulnerabilities. We are using a self-managed cluster. We did upgrade the ELK stack from version 8.13.2 to 8.15.2, but the OpenJDK vulnerabilities still remain unresolved. Current Elasticsearch Version: 8.15.2 Path: /usr/share/elasticsearch/jdk/ Installed Bundled JDK Version: 22.0.1 The reported CVE IDs are: CVE-2024-21131 CVE-2024-21138 CVE-2024-21140 CV…

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [April 21, 2025, 1:47pm UTC](https://discuss.elastic.co/t/elasticsearch-8-15-2-openjdk-cves/377335/3 "2025-04-21T13:47:36Z")

</div>



---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [April 21, 2025, 1:48pm UTC](https://discuss.elastic.co/t/elasticsearch-8-15-2-openjdk-cves/377335/4 "2025-04-21T13:48:42Z")

</div>



---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [April 21, 2025, 1:48pm UTC](https://discuss.elastic.co/t/elasticsearch-8-15-2-openjdk-cves/377335/5 "2025-04-21T13:48:56Z")

</div>


