# Why traffic between filebeat and elasticsearch contains “Apache Struts2 OGNL Remote Code Execution Vulnerability”

**URL:** <https://discuss.elastic.co/t/why-traffic-between-filebeat-and-elasticsearch-contains-apache-struts2-ognl-remote-code-execution-vulnerability/332505>\
**Category:** Elasticsearch\
**Created:** [May 4, 2023, 7:37am UTC](https://discuss.elastic.co/t/why-traffic-between-filebeat-and-elasticsearch-contains-apache-struts2-ognl-remote-code-execution-vulnerability/332505 "2023-05-04T07:37:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![wlane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wlane/32/120615_2.png) [@wlane](https://discuss.elastic.co/u/wlane)\
**Post date:** [May 4, 2023, 7:37am UTC](https://discuss.elastic.co/t/why-traffic-between-filebeat-and-elasticsearch-contains-apache-struts2-ognl-remote-code-execution-vulnerability/332505/1 "2023-05-04T07:37:05Z")

</div>

Hi guys,

We used Filebeat to send application logs to Elasticsearch. And these two components are deployed in different environments with firewall PaloAlto in between.

We found that after transmitting for a period of time, there will be a "connection reset by peer" error in the filebeat log. After investigation, we found the PaloAlto identified this traffic as a threat and detected "apache struts2 ognl remote code execution vulnerability" in this traffic.

I am not sure if Elasticsearch uses the apache struct2 framework, and I checked the security advisories and did not find security issues of this kind, so how did this happen？

Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 4, 2023, 11:41pm UTC](https://discuss.elastic.co/t/why-traffic-between-filebeat-and-elasticsearch-contains-apache-struts2-ognl-remote-code-execution-vulnerability/332505/2 "2023-05-04T23:41:50Z")

</div>

> [@wlane](#):
>
> so how did this happen？

You'd need to ask palo alto, their product is the one doing this.

---

<div class="post-metadata">

**Author:** ![wlane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wlane/32/120615_2.png) [@wlane](https://discuss.elastic.co/u/wlane)\
**Post date:** [May 8, 2023, 1:42am UTC](https://discuss.elastic.co/t/why-traffic-between-filebeat-and-elasticsearch-contains-apache-struts2-ognl-remote-code-execution-vulnerability/332505/3 "2023-05-08T01:42:55Z")

</div>

Thanks, and I think I need to know if Elasticsearch uses the apache struct2 framework before asking Palo Alto.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 8, 2023, 2:44am UTC](https://discuss.elastic.co/t/why-traffic-between-filebeat-and-elasticsearch-contains-apache-struts2-ognl-remote-code-execution-vulnerability/332505/4 "2023-05-08T02:44:07Z")

</div>

Elasticsearch doesn't use struts as far as I know.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2023, 2:44am UTC](https://discuss.elastic.co/t/why-traffic-between-filebeat-and-elasticsearch-contains-apache-struts2-ognl-remote-code-execution-vulnerability/332505/5 "2023-06-05T02:44:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
