# Apache Log4j 2.0 \< 2.3.2 / 2.4 \< 2.12.4 / 2.13 \< 2.17.1 RCE

**URL:** https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614
**Category:** Elasticsearch
**Created:** [January 20, 2023, 4:32pm UTC](https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614 "2023-01-20T16:32:55Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![khadija70](https://avatars.discourse-cdn.com/v4/letter/k/6bbea6/32.png) [@khadija70](https://discuss.elastic.co/u/khadija70)
#### Post date: [January 20, 2023, 4:32pm UTC](https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614/1 "2023-01-20T16:32:55Z")

</div>

Hi ,  
We have recently receive security vulnerabilities related to Log4j , as solution proposed is to Upgrade to Apache Log4j version 2.17.1, 2.12.4, or 2.3.2 or later.  
Could you please confirm if there is a patch to install in order to fix this vulnerabilities , or is it mandatory to upgrade the version of ELK , the versions we have for the ELK cluster are

kibana\_version: '7.15.1'

elasticsearch\_version: '7.15.1'

logstash\_version: '7.15.1'

securityplugin\_version: '1.42.0'

securityplugin\_version\_kibana: '1.42.0'

Thanks

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [January 20, 2023, 4:51pm UTC](https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614/2 "2023-01-20T16:51:09Z")

</div>

You should upgrade to 7.17

---

<div class="post-metadata">

### Author: ![khadija70](https://avatars.discourse-cdn.com/v4/letter/k/6bbea6/32.png) [@khadija70](https://discuss.elastic.co/u/khadija70)
#### Post date: [January 20, 2023, 4:57pm UTC](https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614/3 "2023-01-20T16:57:25Z")

</div>

Thanks foryour answer , for the pluging readonly rest should we also upgrade it or juste the ELK cluster which must be upgrade

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [January 20, 2023, 5:56pm UTC](https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614/4 "2023-01-20T17:56:05Z")

</div>

I have no idea for 3rd party plugins. You should ask them.

---

<div class="post-metadata">

### Author: ![khadija70](https://avatars.discourse-cdn.com/v4/letter/k/6bbea6/32.png) [@khadija70](https://discuss.elastic.co/u/khadija70)
#### Post date: [January 20, 2023, 6:08pm UTC](https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614/5 "2023-01-20T18:08:06Z")

</div>

ok thank you for your reply

---

<div class="post-metadata">

### Author: ![khadija70](https://avatars.discourse-cdn.com/v4/letter/k/6bbea6/32.png) [@khadija70](https://discuss.elastic.co/u/khadija70)
#### Post date: [January 20, 2023, 6:29pm UTC](https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614/6 "2023-01-20T18:29:43Z")

</div>

We also have on elasticsearch serveurs the vulnerability :

151209 (4) - OpenJDK 7 \<= 7u281 / 8 \<= 8u272 / 11.0.0 \<= 11.0.9 / 13.0.0 \<= 13.0.5 / 15.0.0 \<= 15.0.1  
Vulnerability (2021-01-19)

The solution proposed is to upgrade Upgrade to an OpenJDK version greater than 7u281 / 8u272 / 11.0.9 / 13.0.5 / 15.0.1

And on the Kibana , elasticsearch and logstash servers we have also the vulnerability :  
Oracle Java SE Multiple Vulnerabilities

Proposing as solution to apply the appropriate patch according to the January 2023 Oracle Critical Patch Update advisory.

Is the upgrade of ELK should fix those vulnerabilities , otherwise is there any patch for the last one of oracle.

Thanks for help

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [January 20, 2023, 6:51pm UTC](https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614/7 "2023-01-20T18:51:19Z")

</div>

As noted earlier, upgrade to at least version 7.17.8. I believe this comes with a considerable more recent JVM bundled.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 17, 2023, 6:51pm UTC](https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614/8 "2023-02-17T18:51:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
