# What is the fix for CVE-2024-52980 in elasticsearch 7.x versions

**URL:** <https://discuss.elastic.co/t/what-is-the-fix-for-cve-2024-52980-in-elasticsearch-7-x-versions/377099>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [April 14, 2025, 8:03am UTC](https://discuss.elastic.co/t/what-is-the-fix-for-cve-2024-52980-in-elasticsearch-7-x-versions/377099 "2025-04-14T08:03:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Amaresh\_Selva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amaresh_selva/32/65724_2.png) [@Amaresh\_Selva](https://discuss.elastic.co/u/Amaresh_Selva)\
**Post date:** [April 14, 2025, 8:03am UTC](https://discuss.elastic.co/t/what-is-the-fix-for-cve-2024-52980-in-elasticsearch-7-x-versions/377099/1 "2025-04-14T08:03:27Z")

</div>

we are currently using elasticsearch 7.17.26 in our client side and 7.17.24 in servers . we received a notification about CVE-2024-52980 in elasticsearch  
what is the fix for this CVE for 7.x versions  
we only see that it is mentioned that fix is avaialbe in 8.15 versions  
since all our instances are in production grade we cannot upgrade them immediately . isnt there a security patch for elasticsearch 7.x versions

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 14, 2025, 8:22am UTC](https://discuss.elastic.co/t/what-is-the-fix-for-cve-2024-52980-in-elasticsearch-7-x-versions/377099/2 "2025-04-14T08:22:57Z")

</div>

Welcome!

Thank you for your report.

Elastic's security reporting guidelines are available at [Security issues | Elastic](https://www.elastic.co/community/security).

Per those guidelines, all reports of potential security issues or vulnerabilities should be sent via email to [security@elastic.co](mailto:security@elastic.co).

We are unable to discuss potential issues of this nature here. Please send your report to the email address above, where it can be appropriately handled.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [April 16, 2025, 6:28am UTC](https://discuss.elastic.co/t/what-is-the-fix-for-cve-2024-52980-in-elasticsearch-7-x-versions/377099/3 "2025-04-16T06:28:27Z")

</div>

Although @dadoonet is right, we can't discuss the details of security vulnerabilities here, it is worth noting that the 7.x series has now passed the [end of its maintenance term](https://www.elastic.co/support/eol) and will have no more releases. You must upgrade to 8.x to pick up any future improvements (whether security-related or otherwise).

---

<div class="post-metadata">

**Author:** ![Amaresh\_Selva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amaresh_selva/32/65724_2.png) [@Amaresh\_Selva](https://discuss.elastic.co/u/Amaresh_Selva)\
**Post date:** [April 16, 2025, 10:14am UTC](https://discuss.elastic.co/t/what-is-the-fix-for-cve-2024-52980-in-elasticsearch-7-x-versions/377099/4 "2025-04-16T10:14:19Z")

</div>

Thank you @DavidTurner  
Asking this Just to understand for future cases. the vulnerability was filed on 8th April which is 7 days before End of maintainence of 7.17.x version. Will there still be no security patch for this

End of maintainence mentioned as 15th April as per the above link

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [April 16, 2025, 11:17am UTC](https://discuss.elastic.co/t/what-is-the-fix-for-cve-2024-52980-in-elasticsearch-7-x-versions/377099/5 "2025-04-16T11:17:09Z")

</div>

Yes, the end of maintenance is the point at which we stop producing releases, not the point at which we stop accepting new bug reports.
