# How to fix the security problem of the EPR and logstash 8.15.0

**URL:** <https://discuss.elastic.co/t/how-to-fix-the-security-problem-of-the-epr-and-logstash-8-15-0/364997>\
**Category:** Kibana\
**Created:** [August 16, 2024, 6:17am UTC](https://discuss.elastic.co/t/how-to-fix-the-security-problem-of-the-epr-and-logstash-8-15-0/364997 "2024-08-16T06:17:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jevonsnotes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jevonsnotes/32/130317_2.png) [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Post date:** [August 16, 2024, 6:17am UTC](https://discuss.elastic.co/t/how-to-fix-the-security-problem-of-the-epr-and-logstash-8-15-0/364997/1 "2024-08-16T06:17:01Z")

</div>

Elastic Package Registry and logstash has been scanned for the following vulnerabilities，is there anyway to fix them ?

version 8.15.0

EPR:

 ![ebf660a8ce08cab4ce019fb109cff88](https://us1.discourse-cdn.com/elastic/original/3X/6/c/6cf03f34e4f3f747adc132afe8ea54caddd79ab3.png)  
CVE-2023-42365  
CVE-2023-42364  
CVE-2023-42366  
CVE-2023-42363  
CVE-2023-6992  
CVE-2024-7264  
CVE-2024-6197

```auto
busybox 1.36.1-r7 no recommend
zlib 1.3.1-r0 recommend 1.3.1-r1
curl 8.7.1-r0 recommend 8.9.1-r1

```

Logstash

 ![21ccded9aa0c2e4a0752a309ea15bf0](https://us1.discourse-cdn.com/elastic/original/3X/2/3/236bae0d82b442d3007acebae8207687b75e07a3.png)

```auto
rexml 3.3.2 recommend 3.3.3
janino 3.1.0 recommend 3.1.10

```

CVE-2024-41123  
CVE-2024-41946  
CVE-2023-33546  
how to upgrade or remove them?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 16, 2024, 1:15pm UTC](https://discuss.elastic.co/t/how-to-fix-the-security-problem-of-the-epr-and-logstash-8-15-0/364997/2 "2024-08-16T13:15:05Z")

</div>

> [@jevonsnotes](#):
>
> how to upgrade or remove them?

You can't upgrade them, only Elastic can.

You need to send an e-mail to `security@elastic.co` with those CVEs so Elastic can analyse them and decide if they impact Logstash or not.

---

<div class="post-metadata">

**Author:** ![jevonsnotes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jevonsnotes/32/130317_2.png) [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Post date:** [August 19, 2024, 1:19am UTC](https://discuss.elastic.co/t/how-to-fix-the-security-problem-of-the-epr-and-logstash-8-15-0/364997/3 "2024-08-19T01:19:43Z")

</div>

ok，thks @leandrojmp

---

<div class="post-metadata">

**Author:** ![jevonsnotes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jevonsnotes/32/130317_2.png) [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Post date:** [August 19, 2024, 1:26am UTC](https://discuss.elastic.co/t/how-to-fix-the-security-problem-of-the-epr-and-logstash-8-15-0/364997/4 "2024-08-19T01:26:02Z")

</div>

hi,about EPR vulnerability,Can you provide specific repair steps? i don't know how to upgrade them directly.  
I am using the air-gapped docker image of EPR. thks
