# ELK upgrade to 7.17.10

**URL:** <https://discuss.elastic.co/t/elk-upgrade-to-7-17-10/336513>\
**Category:** Elasticsearch\
**Created:** [June 20, 2023, 10:05pm UTC](https://discuss.elastic.co/t/elk-upgrade-to-7-17-10/336513 "2023-06-20T22:05:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![khadija70](https://avatars.discourse-cdn.com/v4/letter/k/6bbea6/32.png) [@khadija70](https://discuss.elastic.co/u/khadija70)\
**Post date:** [June 20, 2023, 10:05pm UTC](https://discuss.elastic.co/t/elk-upgrade-to-7-17-10/336513/1 "2023-06-20T22:05:11Z")

</div>

Hi ,  
We recentely upgraded the ELK cluster from the 7.15.1 to 7.17.10 in order to fix security vulnerabilities , however after upgrading we are still have the open JDK vulnerability on Elasticsearch servers :  
OpenJDK 7 \<= 7u281 / 8 \<= 8u272 / 11.0.0 \<= 11.0.9 / 13.0.0 \<= 13.0.5 /  
15.0.0 \<= 15.0.1 Vulnerability (2021-01-19)

But for kibana and logstach server we don't have this vulnerability  
Could you plase provide help on how to fix that , is it possible to upgrade the openjdk on those elastick search servers whithout upgrading the ELK cluster to a higher version ?  
Or we need to upgrade the whole ELK to 8.6 version .

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 21, 2023, 4:02am UTC](https://discuss.elastic.co/t/elk-upgrade-to-7-17-10/336513/2 "2023-06-21T04:02:22Z")

</div>

You can see JVM and Elasticsearch compatibility here - [Support Matrix | Elastic](https://www.elastic.co/support/matrix#matrix_jvm). If yoou can upgrade to 8.X you will be in a better position, otherwise use OpenJDK 20.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [June 21, 2023, 5:11am UTC](https://discuss.elastic.co/t/elk-upgrade-to-7-17-10/336513/3 "2023-06-21T05:11:10Z")

</div>

And the docs about changing the JDK version are here: [Installing Elasticsearch | Elasticsearch Guide [8.8] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/install-elasticsearch.html#jvm-version)

Note that we strongly recommend using the bundled JDK, since we treat it as a dependency of Elasticsearch. An apparent vulnerability in a dependency such as the JDK is often not a vulnerability in ES, perhaps because ES avoids the vulnerable feature or because it includes other protections which neutralise the problem. If you believe ES (including its bundled JDK) is genuinely vulnerable then please report the problem as per this page: [Security issues | Elastic](https://www.elastic.co/community/security)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2023, 5:12am UTC](https://discuss.elastic.co/t/elk-upgrade-to-7-17-10/336513/4 "2023-07-19T05:12:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
