# CVE-2021-44228 aka log4shell is logstash and/or elasticsearch affected?

**URL:** https://discuss.elastic.co/t/cve-2021-44228-aka-log4shell-is-logstash-and-or-elasticsearch-affected/291415
**Category:** Logstash
**Created:** [December 10, 2021, 11:07am UTC](https://discuss.elastic.co/t/cve-2021-44228-aka-log4shell-is-logstash-and-or-elasticsearch-affected/291415 "2021-12-10T11:07:13Z")
**Posts on this page:** 1
**Showing post:** 13

<div class="post-metadata">

### Author: ![MChat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mchat/32/46467_2.png) [@MChat](https://discuss.elastic.co/u/MChat)
#### Post date: [December 13, 2021, 6:20pm UTC](https://discuss.elastic.co/t/cve-2021-44228-aka-log4shell-is-logstash-and-or-elasticsearch-affected/291415/13 "2021-12-13T18:20:02Z")

</div>

As per Solutions and Mitigations for Logstash on Elastic security announcement - [Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476) , suggests removing JndiLookup class from log4J-core-2\* .

**Solutions and Mitigations:**  
Users should upgrade to Logstash 6.8.21 or 7.16.1 once they are released (expected Monday 13th December). These releases will replace vulnerable versions of Log4j with Log4j 2.15.0.

The widespread flag `-Dlog4j2.formatMsgNoLookups=true` is NOT sufficient to mitigate the vulnerability in Logstash in all cases, as Logstash uses Log4j in a way where the flag has no effect. It is therefore necessary to remove the JndiLookup class from the log4j2 core jar, with the following command:

`zip -q -d <LOGSTASH_HOME>/logstash-core/lib/jars/log4j-core-2.* org/apache/logging/log4j/core/lookup/JndiLookup.class`

Please note that a restart of the Logstash process is necessary for the change to take effect.

Does it apply to Logstash running on JDK 8u302 with JVM argument, "-Dlog4j2.formatMsgNoLookups=true" without updating log4j-core v2.15 ? This blog [Log4Shell: RCE 0-day exploit found in log4j 2, a popular Java logging package | LunaSec](https://www.lunasec.io/docs/blog/log4j-zero-day/) says -

_ **JDK versions greater than `6u211` , `7u201` , `8u191` , and `11.0.1` are not affected by the LDAP attack vector. In these versions `com.sun.jndi.ldap.object.trustURLCodebase` is set to `false` meaning JNDI cannot load remote code using LDAP.** _

---

_[View the full topic](https://discuss.elastic.co/t/cve-2021-44228-aka-log4shell-is-logstash-and-or-elasticsearch-affected/291415)._
