# Kibana 6.1.1 security update

**URL:** <https://discuss.elastic.co/t/kibana-6-1-1-security-update/112520>\
**Category:** Security Announcements\
**Created:** [December 19, 2017, 10:57pm UTC](https://discuss.elastic.co/t/kibana-6-1-1-security-update/112520 "2017-12-19T22:57:22Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)\
**Post date:** [December 19, 2017, 10:57pm UTC](https://discuss.elastic.co/t/kibana-6-1-1-security-update/112520/1 "2017-12-19T22:57:22Z")

</div>

**Kibana arbitrary code execution issue (ESA-2017-24)**  
Kibana version 6.1.0 had an arbitrary code execution vulnerability in the Math.js package which is used by math aggregations in Time Series Visual Builder. Kibana users could construct a math aggregation capable of executing arbitrary code on the Kibana server.

This update removes the math aggregation feature from Kibana which was added in 6.1.0

**Affected Versions:**  
Kibana version 6.1.0 is affected by this flaw. No other versions are affected.

**Solutions and Mitigations:**  
Anyone running Kibana 6.1.0 should upgrade to Kibana version 6.1.1. If you are unable to upgrade, you may set “metrics.enabled: false” in the kibana.yml file to disable the Time Series Visual Builder feature.

**CVE ID:** CVE-2017-1001002

---

_[View the full topic](https://discuss.elastic.co/t/kibana-6-1-1-security-update/112520)._
