# Fixing vulnerablities in logstash code

**URL:** <https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168>\
**Category:** Logstash\
**Created:** [September 15, 2023, 10:23pm UTC](https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168 "2023-09-15T22:23:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![balakr](https://avatars.discourse-cdn.com/v4/letter/b/c89c15/32.png) [@balakr](https://discuss.elastic.co/u/balakr)\
**Post date:** [September 15, 2023, 10:23pm UTC](https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168/1 "2023-09-15T22:23:08Z")

</div>

my company check for vulnerablities and i see bunch of vulnerablities in logstash. an example is below

to fix this vulnerablity, should i upgrade guava or does jruby needs to be upgraded. if jruby needs to be upgraded where can i find what versions of jruby is logstash compatible with.

if i need to upgrade guava seperately where can i find the dependencies map for this

com.google.guava:guava 18.0 24.1.1 Java usr/share/logstash/vendor/bundle/jruby/2.6.0/gems/ruby-maven-libs-3.3.9/maven-home/lib/guava-18.0.jar

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 16, 2023, 5:05am UTC](https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168/2 "2023-09-16T05:05:34Z")

</div>

> [@balakr](#):
>
> to fix this vulnerablity, should i upgrade guava or does jruby needs to be upgraded. if jruby needs to be upgraded where can i find what versions of jruby is logstash compatible with.

None, you cannot upgrade the individual components and libraries used by Logstash, you would need to upgrade to a new Logstash version, if available.

If you are not on the last versions of Logstash which are `7.17.13` for the version 7 and `8.10.0` for the version 8, you need to upgrade to the last version.

If after the upgrade the vulnerability is still being detected, you will need to report it to Elastic through the e-mail `security@elastic.co` and wait for a fix.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2023, 5:06am UTC](https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168/3 "2023-10-14T05:06:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
