# Logstash jdk vulnerability

**URL:** <https://discuss.elastic.co/t/logstash-jdk-vulnerability/343578>\
**Category:** Logstash\
**Created:** [September 21, 2023, 10:03pm UTC](https://discuss.elastic.co/t/logstash-jdk-vulnerability/343578 "2023-09-21T22:03:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![eh2021-elastic](https://avatars.discourse-cdn.com/v4/letter/e/e9bcb4/32.png) [@eh2021-elastic](https://discuss.elastic.co/u/eh2021-elastic)\
**Post date:** [September 21, 2023, 10:03pm UTC](https://discuss.elastic.co/t/logstash-jdk-vulnerability/343578/1 "2023-09-21T22:03:22Z")

</div>

We are currently running logstash 7.16.3 but are getting flagged for the version of JDK 11.0.13 that it is using and are being told we need to upgrade the JDK version to something higher that 11.0.13. How do one upgrade the logstash JDK version since it ships with logstash. We are running elastic 7.16.3 and could look at upgrading to logstash 7.17.x to see if that address the issue.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [September 22, 2023, 11:12am UTC](https://discuss.elastic.co/t/logstash-jdk-vulnerability/343578/2 "2023-09-22T11:12:48Z")

</div>

Hi @eh2021-elastic,

It might be worth upgrading to 7.17.x if you can to ensure you're on a supported version.

Checking the [JVM product compatibility matrix for Logstash](https://staging-website.elastic.co/support/matrix#matrix_jvm) it looks to be that 7.17.x is compatible with 11 and 15 versions. Hopefully upgrading to 7.7.x will resolve the issue, but otherwise I would recommend having a look at configuring [`LS_JAVA_HOME`](https://www.elastic.co/guide/en/logstash/7.17/getting-started-with-logstash.html#java-home).

Hope that helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2023, 11:13am UTC](https://discuss.elastic.co/t/logstash-jdk-vulnerability/343578/3 "2023-10-20T11:13:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
