-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Kibana Knowledge Base Files being detected as Malware after update to 8.16 #202114
Comments
Pinging @elastic/kibana-operations (Team:Operations) |
Not 100% sure this is for Operations team but they'll know better if this is for another team. |
We’re encountering the same issue described here and would like to know if there’s been any progress or updates on this. The problem is impacting our workflow, and we’re eager to understand the current status or any planned fixes. |
This package is owned by @elastic/security-generative-ai. Don't know how much Operations can help with this, but feel free to ping us if something comes up. |
Any news? We had to remove the directory to stop the amount of alerts, but next update it will be back and the issue will start all over again. |
Facing a similar situation to @tammytankian - a large enterprise customer is requesting an "official" bulletin from Elastic prior to accepting this as a false positive. This appears to only be a problem with Defender... |
Hi @oldefortran, the Elastic security team confirms that this is a false positive. The identified files (under |
Much appreciated @peluja1012 - thank you! |
Team @peluja1012 Does the latest Kibana 8.17.0 fix the false positive issue? |
Customer done a virus scan on version 8.17.0 this morning and the anti-virus software identified the same two files are problematic. |
Hi @sheikharsalanelastic, we expect the issue to still be present in 8.17.0, unfortunately. We are working on a potential fix and will prioritize it but we don't currently have a target release date that we can share. |
Thanks |
Thanks. Is there a timeline of when the fix will be available for, I assume 8.17.1? |
@peluja1012 Thanks. Is there a timeline of when the fix will be available for, I assume 8.17.1? |
Hi all, we will most likely target a fix for our 8.18 release. |
Also may be related to https://discuss.elastic.co/t/error-upgrading-kibana-to-newer-version-8-17-0/372577/4.
|
I encountered such like same Issue. In my case is use following OS and ESET,
My machine which has above OS and ESET and Kibana(this Kibane could be installed when ESET stopped.). The ESET detects it as Win32/Filecoder.Cuba ASP/Webshell.CX when Kibana installation. Is Its Kibana safe? |
Kibana version:
8.16.1
Elasticsearch version:
8.16.1
Server OS version:
Debian 12.8
Original install method (e.g. download page, yum, from source, etc.):
Elastic repositories
Describe the bug:
After update to latest version, Kibana knowledge base files on /usr/share/kibana/node_modules/@kbn/elastic-assistant-plugin/server/knowledge_base have been detected as malware by defender.
Steps to reproduce:
Expected behavior:
Not to have any alerts
Screenshots (if relevant):
The text was updated successfully, but these errors were encountered: