# Bug in Log4j mitigation steps in Logstash 5.x

**URL:** https://discuss.elastic.co/t/bug-in-log4j-mitigation-steps-in-logstash-5-x/292612
**Category:** Logstash
**Tags:** elastic-stack-security
**Created:** [December 21, 2021, 8:20pm UTC](https://discuss.elastic.co/t/bug-in-log4j-mitigation-steps-in-logstash-5-x/292612 "2021-12-21T20:20:12Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)
#### Post date: [December 21, 2021, 8:20pm UTC](https://discuss.elastic.co/t/bug-in-log4j-mitigation-steps-in-logstash-5-x/292612/1 "2021-12-21T20:20:12Z")

</div>

There's an excellent article on Logstash remediation to protect against Log4jshell vulnerability - [Logstash 5.0.0-6.8.20 and 7.0.0-7.16.0: Log4j CVE-2021-44228, CVE-2021-45046 remediation](https://discuss.elastic.co/t/logstash-5-0-0-6-8-20-and-7-0-0-7-16-0-log4j-cve-2021-44228-cve-2021-45046-remediation/292343).

However, the steps suggested for Logstash 5.x don't seem to work, especially when using `remove_backup_jndi_lookup.rb`.

Trying to run the the `remove_backup_jndi_lookup.rb` as suggested in the link throws an error on Logstash 5.x nodes. For e.g. assuming the script is located at `/root/remove_backup_jndi_lookup.rb`

```auto
$ vendor/jruby/bin/ruby /root/remove_backup_jndi_lookup.rb
-bash: vendor/jruby/bin/ruby: No such file or directory

$ bin/ruby /root/remove_backup_jndi_lookup.rb
LoadError: no such file to load -- zip
  require at org/jruby/RubyKernel.java:1040
  require at /usr/share/logstash/vendor/jruby/lib/ruby/shared/rubygems/core_ext/kernel_require.rb:54
   (root) at /root/remove_backup_jndi_lookup.rb:7

```

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [December 21, 2021, 8:22pm UTC](https://discuss.elastic.co/t/bug-in-log4j-mitigation-steps-in-logstash-5-x/292612/2 "2021-12-21T20:22:19Z")

</div>

It'd be useful if you could show why you believe it's not working.

But, to be clear, 5.X has been [EOL](https://www.elastic.co/support/eol) for years now, and is no longer supported.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [December 21, 2021, 8:24pm UTC](https://discuss.elastic.co/t/bug-in-log4j-mitigation-steps-in-logstash-5-x/292612/3 "2021-12-21T20:24:54Z")

</div>

@sandeepkanabar

Perhaps it was just a typo but The article you linked to is for remediation for elasticsearch.

The correct article for a remediation of logstash 5.x is this

> [@Logstash 5.0.0-6.8.20 and 7.0.0-7.16.0: Log4j CVE-2021-44228, CVE-2021-45046 remediation](https://discuss.elastic.co/t/logstash-5-0-0-6-8-20-and-7-0-0-7-16-0-log4j-cve-2021-44228-cve-2021-45046-remediation/292343):
>
> Note — These instructions only apply if you are running Logstash 5.0.0 - 6.8.20, or 7.0.0 - 7.16.0. If you are running an older version of Logstash, or a version of Logstash \>= 6.8.21 in the 6.x series or \>= 7.16.1 in the 7.x series, these instructions do not apply. Please follow the guidance in [main announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476)Instructions for removing JndiLookup from relevant JAR files​ These instructions only apply to users running Logstash versions between 5.0.0 and 6.8.20 (inclusive) or between 7.0.0 a…

---

<div class="post-metadata">

### Author: ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)
#### Post date: [December 21, 2021, 8:35pm UTC](https://discuss.elastic.co/t/bug-in-log4j-mitigation-steps-in-logstash-5-x/292612/4 "2021-12-21T20:35:49Z")

</div>

> - On Logstash 5.x.x run  
> `vendor/jruby/bin/ruby /tmp/remove_jndi_lookup.rb`

There's an accidental typo and it should be `vendor/jruby/bin/jruby`. i.e. instead of `ruby` it should be `jruby`.

Fixing this throws another error:

```auto
$ vendor/jruby/bin/jruby /root/remove_backup_jndi_lookup.rb
LoadError: no such file to load -- zip
  require at org/jruby/RubyKernel.java:1040
  require at /usr/share/logstash/vendor/jruby/lib/ruby/shared/rubygems/core_ext/kernel_require.rb:54
   (root) at /root/remove_backup_jndi_lookup.rb:7

```

or using `bin/ruby`

```auto
$ bin/ruby /root/remove_backup_jndi_lookup.rb
LoadError: no such file to load -- zip
  require at org/jruby/RubyKernel.java:1040
  require at /usr/share/logstash/vendor/jruby/lib/ruby/shared/rubygems/core_ext/kernel_require.rb:54
   (root) at /root/remove_backup_jndi_lookup.rb:7

```

From `/usr/share/logstash` dir,

The solution is to set `export GEM_HOME=./vendor/bundle/jruby/1.9` after `deleting jar_backup/` directory and then run  
`vendor/jruby/bin/jruby /<path_to_ruby_script>/remove_backup_jndi_lookup.rb`  
OR  
`bin/ruby /<path_to_ruby_script>/remove_backup_jndi_lookup.rb` and it should complete successfully.

---

<div class="post-metadata">

### Author: ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)
#### Post date: [December 21, 2021, 8:36pm UTC](https://discuss.elastic.co/t/bug-in-log4j-mitigation-steps-in-logstash-5-x/292612/5 "2021-12-21T20:36:22Z")

</div>

Thanks Stephen. Accidentally linked wrong article. Corrected it.

---

<div class="post-metadata">

### Author: ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)
#### Post date: [December 21, 2021, 8:38pm UTC](https://discuss.elastic.co/t/bug-in-log4j-mitigation-steps-in-logstash-5-x/292612/6 "2021-12-21T20:38:23Z")

</div>

Thanks Mark. Updated the question with exact error message and also suggested a possible solution.

Agree, it's EOL. But well, customers 🙂

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 25, 2022, 10:58am UTC](https://discuss.elastic.co/t/bug-in-log4j-mitigation-steps-in-logstash-5-x/292612/8 "2022-01-25T10:58:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
