# HTTP Security Header Not Detected Vulnerability

**URL:** <https://discuss.elastic.co/t/http-security-header-not-detected-vulnerability/109339>\
**Category:** Kibana\
**Created:** [November 28, 2017, 8:43am UTC](https://discuss.elastic.co/t/http-security-header-not-detected-vulnerability/109339 "2017-11-28T08:43:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rachit\_Mohan\_Garg](https://avatars.discourse-cdn.com/v4/letter/r/7cd45c/32.png) [@Rachit\_Mohan\_Garg](https://discuss.elastic.co/u/Rachit_Mohan_Garg)\
**Post date:** [November 28, 2017, 8:43am UTC](https://discuss.elastic.co/t/http-security-header-not-detected-vulnerability/109339/1 "2017-11-28T08:43:01Z")

</div>

Our vulnerability scanning tool, the absence of the following HTTP headers X-Frame-Options, X-XSS-Protection, X-Content-Type-Options has been reported. I want to know how we can rectify this? Is it fixed in the upgraded versions?  
Version we use currently are as below:

Elasticsearch(ELK): 1.2.1  
Logstash(ELK): 1.4.1  
Kibana(ELK): 3.1.0

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 28, 2017, 8:44am UTC](https://discuss.elastic.co/t/http-security-header-not-detected-vulnerability/109339/2 "2017-11-28T08:44:26Z")

</div>

You should _really, really, really_ upgrade. Those are all unsupported versions and have been for years - [https://www.elastic.co/subscriptions/matrix](https://www.elastic.co/subscriptions/matrix)

---

<div class="post-metadata">

**Author:** ![Rachit\_Mohan\_Garg](https://avatars.discourse-cdn.com/v4/letter/r/7cd45c/32.png) [@Rachit\_Mohan\_Garg](https://discuss.elastic.co/u/Rachit_Mohan_Garg)\
**Post date:** [November 28, 2017, 8:46am UTC](https://discuss.elastic.co/t/http-security-header-not-detected-vulnerability/109339/3 "2017-11-28T08:46:01Z")

</div>

Yes @warkolm we are planning to upgrade but till the upgrade is complete we need to take an exception for the vulnerability and for that we need a confirmation if this issue still exists in the latest upgrade or not

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2017, 8:46am UTC](https://discuss.elastic.co/t/http-security-header-not-detected-vulnerability/109339/4 "2017-12-26T08:46:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
