# Bug in Log4j mitigation steps in Logstash 5.x

**URL:** https://discuss.elastic.co/t/bug-in-log4j-mitigation-steps-in-logstash-5-x/292612
**Category:** Logstash
**Tags:** elastic-stack-security
**Created:** [December 21, 2021, 8:20pm UTC](https://discuss.elastic.co/t/bug-in-log4j-mitigation-steps-in-logstash-5-x/292612 "2021-12-21T20:20:12Z")
**Posts on this page:** 1
**Showing post:** 3

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [December 21, 2021, 8:24pm UTC](https://discuss.elastic.co/t/bug-in-log4j-mitigation-steps-in-logstash-5-x/292612/3 "2021-12-21T20:24:54Z")

</div>

@sandeepkanabar

Perhaps it was just a typo but The article you linked to is for remediation for elasticsearch.

The correct article for a remediation of logstash 5.x is this

> [@Logstash 5.0.0-6.8.20 and 7.0.0-7.16.0: Log4j CVE-2021-44228, CVE-2021-45046 remediation](https://discuss.elastic.co/t/logstash-5-0-0-6-8-20-and-7-0-0-7-16-0-log4j-cve-2021-44228-cve-2021-45046-remediation/292343):
>
> Note — These instructions only apply if you are running Logstash 5.0.0 - 6.8.20, or 7.0.0 - 7.16.0. If you are running an older version of Logstash, or a version of Logstash \>= 6.8.21 in the 6.x series or \>= 7.16.1 in the 7.x series, these instructions do not apply. Please follow the guidance in [main announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476)Instructions for removing JndiLookup from relevant JAR files​ These instructions only apply to users running Logstash versions between 5.0.0 and 6.8.20 (inclusive) or between 7.0.0 a…

---

_[View the full topic](https://discuss.elastic.co/t/bug-in-log4j-mitigation-steps-in-logstash-5-x/292612)._
