# CVE-2021-45105 for ELK 7.10.2

**URL:** https://discuss.elastic.co/t/cve-2021-45105-for-elk-7-10-2/292420
**Category:** Elasticsearch
**Created:** [December 20, 2021, 3:46am UTC](https://discuss.elastic.co/t/cve-2021-45105-for-elk-7-10-2/292420 "2021-12-20T03:46:05Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Ram\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ram_n/32/97770_2.png) [@Ram\_N](https://discuss.elastic.co/u/Ram_N)
#### Post date: [December 20, 2021, 3:46am UTC](https://discuss.elastic.co/t/cve-2021-45105-for-elk-7-10-2/292420/1 "2021-12-20T03:46:05Z")

</div>

Hi

Pertaining to 44228, we have deleted the vulnerable class as per ELK suggestion. For this new 45105, do we need to take any action ? I read default Elasticsearch, logstash, Kibana 7.10.2 are not vulnerable. Is that fine?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [December 20, 2021, 3:46am UTC](https://discuss.elastic.co/t/cve-2021-45105-for-elk-7-10-2/292420/2 "2021-12-20T03:46:43Z")

</div>

Welcome to our community! 😃

Please see [Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476) for the full details.

---

<div class="post-metadata">

### Author: ![Ram\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ram_n/32/97770_2.png) [@Ram\_N](https://discuss.elastic.co/u/Ram_N)
#### Post date: [December 20, 2021, 3:49am UTC](https://discuss.elastic.co/t/cve-2021-45105-for-elk-7-10-2/292420/3 "2021-12-20T03:49:45Z")

</div>

Thank you. Im getting confused on there only

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1cdf054a2d70859edb5acc92b080e11bfa6ac420.png)

It says ELK not vulnerable due to this. But still there is release from ELK to mitigate the same. So my question , is upgrade neccessary to mitigate 45105

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [December 20, 2021, 3:51am UTC](https://discuss.elastic.co/t/cve-2021-45105-for-elk-7-10-2/292420/4 "2021-12-20T03:51:35Z")

</div>

I would upgrade anyway, so that you are totally safe as we updated the underlying packages with the issue. It'll stop any false positives if you run scans, and you can safely say you have no deployments of the impacted package as well.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 17, 2022, 3:51am UTC](https://discuss.elastic.co/t/cve-2021-45105-for-elk-7-10-2/292420/5 "2022-01-17T03:51:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
