we’re happy to announce that Search Guard 24.3, compatible with Elasticsearch 6.4.x and above has been released. This also includes support for the newest Elasticsearch 6.7.0 release.
SG 24.3 fixes two critical security issues with Cross Cluster Search (CCS). Every release before 6.x-24.3 for ES 6 is vulnerable and you are strongly advised to upgrade immediately. If you are running on 6.0.x/6.1.x/6.2.x or 6.3.x you need to upgrade to at least 6.4.x.
If you do not use Cross Cluster Search your cluster is not affected by these issues and there is no need to upgrade immediately.
Alongside with the Search Guard release, we also published a bugfix release for the Kibana plugin, which is at version 18.3 at the moment.
As always, thanks for your support and input!
Jochen and the Search Guard team
Search Guard (®) is an Elasticsearch plugin that offers encryption, authentication, and authorization.
Still coded with love in Berlin, Denmark, Sweden, and the US.
Search Guard is a trademark of floragunn GmbH, registered in the U.S. and in other countries.
Elasticsearch, Kibana, Logstash, and Beats are trademarks of Elasticsearch BV, registered in the U.S. and in other countries.