# Elasticsearch 5.0.0-5.6.10 and 6.0.0-6.3.2: Log4j CVE-2021-44228, CVE-2021-45046 remediation

**URL:** https://discuss.elastic.co/t/elasticsearch-5-0-0-5-6-10-and-6-0-0-6-3-2-log4j-cve-2021-44228-cve-2021-45046-remediation/292054
**Category:** Security Announcements
**Created:** [December 15, 2021, 10:21pm UTC](https://discuss.elastic.co/t/elasticsearch-5-0-0-5-6-10-and-6-0-0-6-3-2-log4j-cve-2021-44228-cve-2021-45046-remediation/292054 "2021-12-15T22:21:00Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![qhoxie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/qhoxie/32/47252_2.png) [@qhoxie](https://discuss.elastic.co/u/qhoxie)
#### Post date: [December 15, 2021, 10:21pm UTC](https://discuss.elastic.co/t/elasticsearch-5-0-0-5-6-10-and-6-0-0-6-3-2-log4j-cve-2021-44228-cve-2021-45046-remediation/292054/1 "2021-12-15T22:21:00Z")

</div>

**Note — If you are not running Elasticsearch 5.0.0-5.6.10 or 6.0.0-6.3.2, these instructions do not apply. Please follow the guidance in the [main announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476).**

### Instructions for removing JndiLookup from the log4j-core JAR file​

These instructions only apply to users running Elasticsearch versions between 5.0.0 and 5.6.10 (inclusive) or between 6.0.0 and 6.3.2 (inclusive). These must not be used in other versions of Elasticsearch as there are safer, supported remediations (or no remediation is necessary).

​  
**Note:** These instructions require making manual changes to files within the Elasticsearch installation. Such changes always carry a degree of risk and Elastic's recommendation is to upgrade to a supported version of Elasticsearch in preference to manual patching.

​

#### On Linux or MacOS​

1. These instructions assume the existence of the `zip` utility on your operating system. You can confirm that `zip` is available by entering `zip` in a terminal window. If the output includes copyright text and a list of options, then the "zip" utility is available. If the output is an error message such as

​

1. These instructions must be executed as a user that has write access to the Elasticsearch `lib/` directory (and the files within it). The correct user will depend on how you installed Elasticsearch. If you encounter `Permission denied` errors during this process, please check that you are logged in as the correct user.

​

1. In a terminal window, change your working directory (`cd`) to the root directory for your Elasticsearch installation. For installations from `zip` or `tar` files, this is the directory where you installed Elasticsearch. For installations from RPM or Debian (`.deb`) packages, this will be `/usr/share/elasticsearch`.

​

1. Confirm that you are in the correct directory, and that the log4j file exists with:

2. Make a backup of the vulnerable log4j JAR file with:

​

1. Remove the vulnerable class from your log4j JAR file with:

​

1. Confirm the removal of the vulnerable class with:

​

1. Restart the Elasticsearch node

​

1. Repeat these steps for every Elasticsearch node in your cluster

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 4, 2022, 8:33am UTC](https://discuss.elastic.co/t/elasticsearch-5-0-0-5-6-10-and-6-0-0-6-3-2-log4j-cve-2021-44228-cve-2021-45046-remediation/292054/2 "2022-11-04T08:33:25Z")

</div>


