# Info about CVE-2024-37287

**URL:** <https://discuss.elastic.co/t/info-about-cve-2024-37287/364587>\
**Category:** Kibana\
**Tags:** docker\
**Created:** [August 8, 2024, 8:28am UTC](https://discuss.elastic.co/t/info-about-cve-2024-37287/364587 "2024-08-08T08:28:24Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![lorepas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lorepas/32/136632_2.png) [@lorepas](https://discuss.elastic.co/u/lorepas)\
**Post date:** [August 8, 2024, 8:28am UTC](https://discuss.elastic.co/t/info-about-cve-2024-37287/364587/1 "2024-08-08T08:28:24Z")

</div>

Hi all,  
I noticed the following [security update](https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/364424) regarding the **CVE-2024-37287**. I would like to understand if it could be affected also an on-prem installation of Kibana (v7.17.7) made with rpm, so without docker.

I'm a little bit confused by the following point:

> This issue affects self-managed Kibana installations on host Operating Systems.

Thank you very much!

Lorenzo

---

<div class="post-metadata">

**Author:** ![lorepas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lorepas/32/136632_2.png) [@lorepas](https://discuss.elastic.co/u/lorepas)\
**Post date:** [August 8, 2024, 10:42am UTC](https://discuss.elastic.co/t/info-about-cve-2024-37287/364587/2 "2024-08-08T10:42:15Z")

</div>

Removed #elastic-stack-security

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 8, 2024, 1:40pm UTC](https://discuss.elastic.co/t/info-about-cve-2024-37287/364587/3 "2024-08-08T13:40:01Z")

</div>

> [@lorepas](#):
>
> This issue affects self-managed Kibana installations on host Operating Systems.

If I'm not wrong this means that it affects Kibana instances running on bare metal and VMs, no matter if you installed using deb, rpm or tar.gz

So yes, this seems to affect your on-prem installation.

---

<div class="post-metadata">

**Author:** ![lorepas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lorepas/32/136632_2.png) [@lorepas](https://discuss.elastic.co/u/lorepas)\
**Post date:** [August 8, 2024, 2:22pm UTC](https://discuss.elastic.co/t/info-about-cve-2024-37287/364587/4 "2024-08-08T14:22:29Z")

</div>

Thank you very much @leandrojmp to solve my doubts!

---

<div class="post-metadata">

**Author:** ![A\_B1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b1/32/123474_2.png) [@A\_B1](https://discuss.elastic.co/u/A_B1)\
**Post date:** [August 26, 2024, 8:27am UTC](https://discuss.elastic.co/t/info-about-cve-2024-37287/364587/5 "2024-08-26T08:27:46Z")

</div>

Hi, does this vulnerability also affect kibana 6.1.1?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 26, 2024, 8:41am UTC](https://discuss.elastic.co/t/info-about-cve-2024-37287/364587/6 "2024-08-26T08:41:05Z")

</div>

@A_B1 If CVEs are a concern (which they should), please do no use 6.1.1. It's toooooo old.  
7.17.latest at the very least or 8.15.0!

---

<div class="post-metadata">

**Author:** ![A\_B1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b1/32/123474_2.png) [@A\_B1](https://discuss.elastic.co/u/A_B1)\
**Post date:** [August 26, 2024, 9:52am UTC](https://discuss.elastic.co/t/info-about-cve-2024-37287/364587/7 "2024-08-26T09:52:32Z")

</div>

well for some reasons, I have to use 6.1.1 version for now, do you know if this vulnerability is in this version either or not?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 26, 2024, 10:04am UTC](https://discuss.elastic.co/t/info-about-cve-2024-37287/364587/8 "2024-08-26T10:04:56Z")

</div>

No I don't know.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 26, 2024, 12:51pm UTC](https://discuss.elastic.co/t/info-about-cve-2024-37287/364587/9 "2024-08-26T12:51:22Z")

</div>

Version 6.X is not supported anymore, Elastic only checks if there are any vulnerabilities in supported versions.
