# CVE-2021-45046 : Incomplete fix for Apache Log4j vulnerability

**URL:** https://discuss.elastic.co/t/cve-2021-45046-incomplete-fix-for-apache-log4j-vulnerability/291925
**Category:** Logstash
**Created:** [December 15, 2021, 8:46am UTC](https://discuss.elastic.co/t/cve-2021-45046-incomplete-fix-for-apache-log4j-vulnerability/291925 "2021-12-15T08:46:10Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Ravi\_GH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ravi_gh/32/71311_2.png) [@Ravi\_GH](https://discuss.elastic.co/u/Ravi_GH)
#### Post date: [December 15, 2021, 8:46am UTC](https://discuss.elastic.co/t/cve-2021-45046-incomplete-fix-for-apache-log4j-vulnerability/291925/1 "2021-12-15T08:46:10Z")

</div>

With respect to "Incomplete fix for Apache Log4j vulnerability" @ [Incomplete fix for Apache Log4j vulnerability · CVE-2021-45046 · GitHub Advisory Database · GitHub](https://github.com/advisories/GHSA-7rjr-3q55-vv33)  
I have two questions:

Q1) is JndiLookup class removal break any functionality of Logstash? ( in other words is it safe to remove JndiLookup class file? )  
Q2) As per "On recent JDKs the attack is limited to DoS - causing data ingestion to temporarily stop - and information leakage" extract from [**ESA-2021-31**](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476)\*\* . What is the recommendation to mitigate this DoS attack ( considering java is recent version 8u3xx)?

---

<div class="post-metadata">

### Author: ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)
#### Post date: [December 15, 2021, 9:13pm UTC](https://discuss.elastic.co/t/cve-2021-45046-incomplete-fix-for-apache-log4j-vulnerability/291925/2 "2021-12-15T21:13:46Z")

</div>

Q1) is JndiLookup class removal break any functionality of Logstash? ( in other words is it safe to remove JndiLookup class file? )

IFF your `config/log4j2.properties` was intentionally modified to include JNDI lookups, those lookups would no longer work. I can think of no reason why someone would do this intentionally.

It is safe to remove the JndiLookup class file, which is why it is one of two recommended mitigations

* * *

Q2) As per "On recent JDKs the attack is limited to DoS - causing data ingestion to temporarily stop - and information leakage" extract from [**ESA-2021-31**](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476)\*\* . What is the recommendation to mitigate this DoS attack ( considering java is recent version 8u3xx)?

The recommended mitigations per [ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476) remain:

> [@Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476/1):
>
> Users should upgrade to Logstash [7.16.2](https://www.elastic.co/downloads/logstash) or [6.8.22](https://elastic.co/downloads/past-releases/logstash-6-8-22), which were released on December 19, 2021. These releases replace vulnerable versions of Log4j with Log4j 2.17.0.
> 
> The widespread flag -Dlog4j2.formatMsgNoLookups=true is NOT sufficient to mitigate the vulnerability in Logstash in all cases, as Logstash uses Log4j in a way where the flag has no effect. If the user cannot upgrade to Logstash 7.16.2 or 6.8.22, it is necessary to remove the JndiLookup class from the log4j2 core jar, with the following command (which is applicable for 5.x, 6.x, and 7.x):

[EDIT: updated to reflect guidance in light of the 2021-12-19 releases of Logstash 7.16.2 and 6.8.22]

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 12, 2022, 9:14pm UTC](https://discuss.elastic.co/t/cve-2021-45046-incomplete-fix-for-apache-log4j-vulnerability/291925/3 "2022-01-12T21:14:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
