# Open SSL vulnerability in logstash directory

**URL:** <https://discuss.elastic.co/t/open-ssl-vulnerability-in-logstash-directory/341982>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [August 30, 2023, 12:27pm UTC](https://discuss.elastic.co/t/open-ssl-vulnerability-in-logstash-directory/341982 "2023-08-30T12:27:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Supriyo](https://avatars.discourse-cdn.com/v4/letter/s/c89c15/32.png) [@Supriyo](https://discuss.elastic.co/u/Supriyo)\
**Post date:** [August 30, 2023, 12:27pm UTC](https://discuss.elastic.co/t/open-ssl-vulnerability-in-logstash-directory/341982/1 "2023-08-30T12:27:19Z")

</div>

Security scans have found this open SSL vulnerability in logstash directory.  
We are trying to upgrade OpenSSL version 3.0.8 or later in the production server. The current version on the server is 3.0.3.

Could you please suggest any way to upgrade the OpenSSL to the same log stash version? We are using Logstash 6.4.0

What will be the impact if we delete the existing OpenSSL folder?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 30, 2023, 1:12pm UTC](https://discuss.elastic.co/t/open-ssl-vulnerability-in-logstash-directory/341982/2 "2023-08-30T13:12:32Z")

</div>

It is not sure what openssl you are referring to since you didn't share anything, but you cannot remove or update anything inside the logstash folder.

You will need to update the entire logstash, also 6.4.0 is not supported anymore, it already reached EOL.

You should update to 7.17 or 8.9.

---

<div class="post-metadata">

**Author:** ![Supriyo](https://avatars.discourse-cdn.com/v4/letter/s/c89c15/32.png) [@Supriyo](https://discuss.elastic.co/u/Supriyo)\
**Post date:** [August 31, 2023, 7:58am UTC](https://discuss.elastic.co/t/open-ssl-vulnerability-in-logstash-directory/341982/3 "2023-08-31T07:58:40Z")

</div>

Thank you for the information.

There is some backward compatibility issue so we won't be able to upgrade to 7.17 or 8.9  
But we can do 6.8.23  
Could you please confirm if version 6.8.23 doesn't have the vulnerability CVE20233446?

[nvd.nist.gov/vuln/detail/CVE-2023-3446](http://nvd.nist.gov/vuln/detail/CVE-2023-3446)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 31, 2023, 12:41pm UTC](https://discuss.elastic.co/t/open-ssl-vulnerability-in-logstash-directory/341982/4 "2023-08-31T12:41:19Z")

</div>

> [@Supriyo](#):
>
> Could you please confirm if version 6.8.23 doesn't have the vulnerability CVE20233446?

6.8 is also not supported anymore, it reached EOL february last year, so any new vulnerabilities will not be fixed.

You will need to install it and check if the openssl version is vulnerable or not for this CVE, I do not run 6.8 anymore.

---

<div class="post-metadata">

**Author:** ![Supriyo](https://avatars.discourse-cdn.com/v4/letter/s/c89c15/32.png) [@Supriyo](https://discuss.elastic.co/u/Supriyo)\
**Post date:** [September 1, 2023, 5:01am UTC](https://discuss.elastic.co/t/open-ssl-vulnerability-in-logstash-directory/341982/5 "2023-09-01T05:01:56Z")

</div>

Thank you very much @leandrojmp

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2023, 5:02am UTC](https://discuss.elastic.co/t/open-ssl-vulnerability-in-logstash-directory/341982/6 "2023-09-29T05:02:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
