We are downloading elastic images of docker hub. Elastic image is showing log4j vulnerabilities in 8.5.3 and 8.6 the images released in Dec 2022 and Jan2023. These vulnerabilities were addressed a year ago in dec 2021. Can you please confirm these are false positives. We use sysdig scanner

CriticalReported byNational Vulnerability Database


org.apache.logging.log4j:log4j-slf4j-impl - 2.12.4JAVA

In Use

Package Path


As per Security issues | Elastic, please email security@elastic.co for questions regarding issues.

