# Fix log4j ：upgrade ES version OR replace log4j.jar to 2.17.2

**URL:** https://discuss.elastic.co/t/fix-log4j-upgrade-es-version-or-replace-log4j-jar-to-2-17-2/302786
**Category:** Elasticsearch
**Created:** [April 20, 2022, 9:29am UTC](https://discuss.elastic.co/t/fix-log4j-upgrade-es-version-or-replace-log4j-jar-to-2-17-2/302786 "2022-04-20T09:29:57Z")
**Posts on this page:** 1
**Showing post:** 3

<div class="post-metadata">

### Author: ![qiuxb](https://avatars.discourse-cdn.com/v4/letter/q/48db29/32.png) [@qiuxb](https://discuss.elastic.co/u/qiuxb)
#### Post date: [April 20, 2022, 9:49am UTC](https://discuss.elastic.co/t/fix-log4j-upgrade-es-version-or-replace-log4j-jar-to-2-17-2/302786/3 "2022-04-20T09:49:08Z")

</div>

Thank you, if I can't use the solution of replacing the jar package,  
can I refer to this solution ：

> [@Elasticsearch 5.0.0-5.6.10 and 6.0.0-6.3.2: Log4j CVE-2021-44228, CVE-2021-45046 remediation](https://discuss.elastic.co/t/elasticsearch-5-0-0-5-6-10-and-6-0-0-6-3-2-log4j-cve-2021-44228-cve-2021-45046-remediation/292054):
>
> Note — If you are not running Elasticsearch 5.0.0-5.6.10 or 6.0.0-6.3.2, these instructions do not apply. Please follow the guidance in the [main announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476). Instructions for removing JndiLookup from the log4j-core JAR file​ These instructions only apply to users running Elasticsearch versions between 5.0.0 and 5.6.10 (inclusive) or between 6.0.0 and 6.3.2 (inclusive). These must not be used in other versions of Elasticsearch as there are safer, supported remediations (or no remediation is ne…

---

_[View the full topic](https://discuss.elastic.co/t/fix-log4j-upgrade-es-version-or-replace-log4j-jar-to-2-17-2/302786)._
