# CVE-2021-44228 not using XPack, does exposure change?

**URL:** https://discuss.elastic.co/t/cve-2021-44228-not-using-xpack-does-exposure-change/292022
**Category:** Elasticsearch
**Created:** [December 15, 2021, 4:59pm UTC](https://discuss.elastic.co/t/cve-2021-44228-not-using-xpack-does-exposure-change/292022 "2021-12-15T16:59:37Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [December 16, 2021, 1:18am UTC](https://discuss.elastic.co/t/cve-2021-44228-not-using-xpack-does-exposure-change/292022/2 "2021-12-16T01:18:52Z")

</div>

Nothing in the [security announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476) for this issue is specific to which plugins you have installed or the number of nodes in your cluster.

You should follow the recommendations in that announcement.

---

_[View the full topic](https://discuss.elastic.co/t/cve-2021-44228-not-using-xpack-does-exposure-change/292022)._
