# CVE-2021-44228 not using XPack, does exposure change?

**URL:** https://discuss.elastic.co/t/cve-2021-44228-not-using-xpack-does-exposure-change/292022
**Category:** Elasticsearch
**Created:** [December 15, 2021, 4:59pm UTC](https://discuss.elastic.co/t/cve-2021-44228-not-using-xpack-does-exposure-change/292022 "2021-12-15T16:59:37Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![falcon404](https://avatars.discourse-cdn.com/v4/letter/f/e9bcb4/32.png) [@falcon404](https://discuss.elastic.co/u/falcon404)
#### Post date: [December 15, 2021, 4:59pm UTC](https://discuss.elastic.co/t/cve-2021-44228-not-using-xpack-does-exposure-change/292022/1 "2021-12-15T16:59:37Z")

</div>

Hi,  
We are running Elasticsearch and not enabling / installing X-Pack for reasons.

With regard to the log4j2 vulnerability CVE-2021-44228, there has been mention of setting property or upgrading to a later version (I believe this was 7.8+ now on Java 9 or higher, but its not vital to my question)

My question is if we do not run X-Pack, are we still vulnerable?

- When setting the JVM property, is the fix affected by presence of X-Pack?
- When upgrading to 7.8+ is the fix dependent on the presence of X-Pack?

Follow up question:  
We run most of our nodes in "single-node" mode, not cluster.

Elasticsearch.yml  
discovery.type: single-node

Single node mode to my understanding already skips startup checks and is different in some ways from running it in "production / cluster mode"

Does this affect the proposed vulnerability fix at all?

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [December 16, 2021, 1:18am UTC](https://discuss.elastic.co/t/cve-2021-44228-not-using-xpack-does-exposure-change/292022/2 "2021-12-16T01:18:52Z")

</div>

Nothing in the [security announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476) for this issue is specific to which plugins you have installed or the number of nodes in your cluster.

You should follow the recommendations in that announcement.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 13, 2022, 1:19am UTC](https://discuss.elastic.co/t/cve-2021-44228-not-using-xpack-does-exposure-change/292022/3 "2022-01-13T01:19:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
