Update to kibana 8.17.8 needed for CVE-2025-2135

Elasticsearch version:

8.17.6

Kibana version (if relevant):

8.17.6

Describe the issue:

Elastic issued an important security alert Kibana 7.17.29, 8.17.8, 8.18.3, 9.0.3 Security Update (ESA-2025-09) - Security Announcements - Discuss the Elastic Stack that needs an update to 8.17.8 or 8.18.3. Is any upgrade scheduled ?
It’s not marked as available at https://docs.search-guard.com/latest/search-guard-versions.

@fbacchella Thank you for your question. Please see below the links for the necessary plugins:

FLX 3.0.3 for ES 8.17.8: https://maven.search-guard.com/search-guard-flx-release/com/floragunn/search-guard-flx-elasticsearch-plugin/3.0.3-es-8.17.8/search-guard-flx-elasticsearch-plugin-3.0.3-es-8.17.8.zip

FLX 3.0.3 for Kibana 8.17.8: https://maven.search-guard.com/search-guard-flx-release/com/floragunn/search-guard-flx-kibana-plugin/3.0.3-es-8.17.8/search-guard-flx-kibana-plugin-3.0.3-es-8.17.8.zip

The version matrix will be updated shortly.

The ES plugin for 8.18.3 is available, but not the kibana one.

Thank’ it’s fixed.

The SG version matrix has now been updated with relevant versions.

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.