# Fixing vulnerablities in logstash code

**URL:** <https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168>\
**Category:** Logstash\
**Created:** [September 15, 2023, 10:23pm UTC](https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168 "2023-09-15T22:23:08Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 16, 2023, 5:05am UTC](https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168/2 "2023-09-16T05:05:34Z")

</div>

> [@balakr](#):
>
> to fix this vulnerablity, should i upgrade guava or does jruby needs to be upgraded. if jruby needs to be upgraded where can i find what versions of jruby is logstash compatible with.

None, you cannot upgrade the individual components and libraries used by Logstash, you would need to upgrade to a new Logstash version, if available.

If you are not on the last versions of Logstash which are `7.17.13` for the version 7 and `8.10.0` for the version 8, you need to upgrade to the last version.

If after the upgrade the vulnerability is still being detected, you will need to report it to Elastic through the e-mail `security@elastic.co` and wait for a fix.

---

_[View the full topic](https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168)._
