# CVE-2020-9488 vulnerabilities with java apm agent 1.34.1

**URL:** https://discuss.elastic.co/t/cve-2020-9488-vulnerabilities-with-java-apm-agent-1-34-1/319055
**Category:** APM
**Tags:** java
**Created:** [November 16, 2022, 10:22am UTC](https://discuss.elastic.co/t/cve-2020-9488-vulnerabilities-with-java-apm-agent-1-34-1/319055 "2022-11-16T10:22:40Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![vin89](https://avatars.discourse-cdn.com/v4/letter/v/34f0e0/32.png) [@vin89](https://discuss.elastic.co/u/vin89)
#### Post date: [November 16, 2022, 10:22am UTC](https://discuss.elastic.co/t/cve-2020-9488-vulnerabilities-with-java-apm-agent-1-34-1/319055/1 "2022-11-16T10:22:40Z")

</div>

After we have upgraded apm to 1.34.1, we are still seeing vulnerability CVE-2020-9488 showing up in our application scan reports (earlier we were using 1.28.4)

Expected log4j fix version is 2.13.2 but where in apm 1.34.1, it is still having 2.12.4. So are there any plans to increase log4j version or is it the max version that will be supported?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f5082812c6fe2d4c09a3ff4398c15c0447b6f579.png)

---

<div class="post-metadata">

### Author: ![Jack\_Shirazi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_shirazi/32/91641_2.png) [@Jack\_Shirazi](https://discuss.elastic.co/u/Jack_Shirazi)
#### Post date: [November 16, 2022, 11:09am UTC](https://discuss.elastic.co/t/cve-2020-9488-vulnerabilities-with-java-apm-agent-1-34-1/319055/2 "2022-11-16T11:09:32Z")

</div>

[NVD - cve-2020-9488](https://nvd.nist.gov/vuln/detail/cve-2020-9488) Fixed in Apache Log4j **2.12.3** and 2.13.1  
Please contact your vulnerability scanner vendor and ask them to correct the false positive error

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 7, 2022, 7:10am UTC](https://discuss.elastic.co/t/cve-2020-9488-vulnerabilities-with-java-apm-agent-1-34-1/319055/3 "2022-12-07T07:10:01Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
