# Node.js vulnerabilities

**URL:** <https://discuss.elastic.co/t/node-js-vulnerabilities/359102>\
**Category:** Kibana\
**Created:** [May 8, 2024, 7:33pm UTC](https://discuss.elastic.co/t/node-js-vulnerabilities/359102 "2024-05-08T19:33:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jloas](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@jloas](https://discuss.elastic.co/u/jloas)\
**Post date:** [May 8, 2024, 7:33pm UTC](https://discuss.elastic.co/t/node-js-vulnerabilities/359102/1 "2024-05-08T19:33:24Z")

</div>

We use Elasticsearch/Kibana and we continually have our scanners flagging node.js vulnerabilities b/c the version of node.js is present in our applications/on our nodes. The issue is Elastic has not called out any of these CVE's as impacting Elasticsearch or Kibana. So my assumption is that even though the version of node.js that has open CVE's is present in our deployment, Elastic has determined the functionality impacted by this CVE is not used in Elasticsearch/Kibana. Or, Elasticsearch/Kibana is not impacted for some other reason. I am trying to test the assumption that if Elastic does not report they are impacted by a CVE then it's safe to assume the CVE is n/a. Furthermore, if the CVE is not listed here then it's N/A: [Security Announcements - Discuss the Elastic Stack](https://discuss.elastic.co/c/announcements/security-announcements/31)

CVE-2024-27983, CVE-2024-27982,CVE-2023-46809, CVE-2024-21890, CVE-2024-21891, CVE-2024-21892, CVE-2024-21896, CVE-2024-22017, CVE-2024-22019

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [May 10, 2024, 8:46am UTC](https://discuss.elastic.co/t/node-js-vulnerabilities/359102/2 "2024-05-10T08:46:28Z")

</div>

Hey @jloas ,

Can you please share the Elastic Stack version you're using?

Also, please send any questions regarding security statements and CVEs to [security@elastic.co](mailto:security@elastic.co). The team will happily provide you with the necessary information.

--  
Oleg

---

<div class="post-metadata">

**Author:** ![jloas](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@jloas](https://discuss.elastic.co/u/jloas)\
**Post date:** [May 10, 2024, 1:07pm UTC](https://discuss.elastic.co/t/node-js-vulnerabilities/359102/3 "2024-05-10T13:07:03Z")

</div>

8.13.2 basic free version. I know this has node.js 20.12.1.

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [May 10, 2024, 2:30pm UTC](https://discuss.elastic.co/t/node-js-vulnerabilities/359102/4 "2024-05-10T14:30:24Z")

</div>

> [@jloas](#):
>
> 8.13.2 basic free version. I know this has node.js 20.12.1.

I see, please email to [security@elastic.co](mailto:security@elastic.co), I'm pretty sure we have official statements for all these CVEs (I recognize many of them) so that you don't have to guess.
