# Vulnerabilities in latest docker image of Elasticsearch 8.3.1

**URL:** https://discuss.elastic.co/t/vulnerabilities-in-latest-docker-image-of-elasticsearch-8-3-1/310031
**Category:** Elasticsearch
**Tags:** docker
**Created:** [July 19, 2022, 1:57pm UTC](https://discuss.elastic.co/t/vulnerabilities-in-latest-docker-image-of-elasticsearch-8-3-1/310031 "2022-07-19T13:57:31Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![chitransh\_1](https://avatars.discourse-cdn.com/v4/letter/c/5e9695/32.png) [@chitransh\_1](https://discuss.elastic.co/u/chitransh_1)
#### Post date: [July 19, 2022, 1:57pm UTC](https://discuss.elastic.co/t/vulnerabilities-in-latest-docker-image-of-elasticsearch-8-3-1/310031/1 "2022-07-19T13:57:31Z")

</div>

Hi,

We are using Elasticsearch 8.3.1 for one of our projects.  
While scanning the Elasticsearch 8.3.1 with Aquasec Scanner, we are getting a few CVEs:

These CVE are associated with various Java based packages which have high vulnerabilities associated:  
CVE-2021-40690 xmlsec 2.1.4  
CVE-2020-36518 jackson-databind 2.13.2  
CVE-2020-36518 jackson-databind 2.13.1  
CVE-2021-31684 json-smart 1.3.2

I even tried pulling the latest image which is 8.3.2 at the time of writing this which yields the same results.

How are xmlsec, jackson-databind, json-smart being used in Elasticsearch.  
Would it be possible to update the packages in Elasticsearch?

Edit: Our datahub deployment failed with Elasticsearch 8.3.1. We are forced to use 7.16.2 as datahub isn't compatible with versions after that. Is it possible to release a version/bugfix with these vulnerability resolutions:  
CVE Package Fixed Version Published by NVD  
CVE-2020-25649 jackson-databind 2.10.4 2.10.5.1 2020-12-03  
CVE-2020-36518 jackson-databind 2.10.4 2.12.6.1 2022-03-11  
CVE-2021-37136 netty-codec 4.1.66.Final 4.1.68.Final 2021-10-19  
CVE-2021-37137 netty-codec 4.1.66.Final 4.1.68.Final 2021-10-19  
CVE-2021-31684 json-smart 1.3.2 2.4.5 2021-06-01  
CVE-2021-40690 xmlsec 2.1.4 2.1.7 2021-09-19  
CVE-2020-28491 jackson-dataformat-cbor 2.10.4 2.11.4 2021-02-18

Thanks and regards  
Chitransh Teotia

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [July 19, 2022, 9:30pm UTC](https://discuss.elastic.co/t/vulnerabilities-in-latest-docker-image-of-elasticsearch-8-3-1/310031/2 "2022-07-19T21:30:13Z")

</div>

Please see [Security issues | Elastic](https://www.elastic.co/community/security);

> Users and customers may report any other potential security issues to [security@elastic.co](mailto:security@elastic.co). This address can be used for product security related inquiries or requests about other security topics that are not explicitly mentioned here.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 16, 2022, 9:31pm UTC](https://discuss.elastic.co/t/vulnerabilities-in-latest-docker-image-of-elasticsearch-8-3-1/310031/3 "2022-08-16T21:31:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
