# Log4j CVE-2021-44832 (released 28th dec) - is ES vulnerable?

**URL:** <https://discuss.elastic.co/t/log4j-cve-2021-44832-released-28th-dec-is-es-vulnerable/293076>\
**Category:** Elasticsearch\
**Created:** [December 29, 2021, 12:08am UTC](https://discuss.elastic.co/t/log4j-cve-2021-44832-released-28th-dec-is-es-vulnerable/293076 "2021-12-29T00:08:36Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vashiru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vashiru/32/99623_2.png) [@Vashiru](https://discuss.elastic.co/u/Vashiru)\
**Post date:** [December 29, 2021, 12:08am UTC](https://discuss.elastic.co/t/log4j-cve-2021-44832-released-28th-dec-is-es-vulnerable/293076/1 "2021-12-29T00:08:36Z")

</div>

As the title states, is Elasticsearch vulnerable for the new Log4j vulnerability [CVE-2021-44832](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44832)? This is a new vulnerability of which the details were released a few hours ago. Or is this prevented by the security manager?

---

<div class="post-metadata">

**Author:** ![Chiranjiv\_Choudhary](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chiranjiv_choudhary/32/53898_2.png) [@Chiranjiv\_Choudhary](https://discuss.elastic.co/u/Chiranjiv_Choudhary)\
**Post date:** [December 29, 2021, 3:30pm UTC](https://discuss.elastic.co/t/log4j-cve-2021-44832-released-28th-dec-is-es-vulnerable/293076/2 "2021-12-29T15:30:20Z")

</div>

Is there any update on [Log4j CVE-2021-44832] from Elasticsearch yet ?

---

<div class="post-metadata">

**Author:** ![jeansalama](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeansalama/32/99721_2.png) [@jeansalama](https://discuss.elastic.co/u/jeansalama)\
**Post date:** [December 31, 2021, 5:15pm UTC](https://discuss.elastic.co/t/log4j-cve-2021-44832-released-28th-dec-is-es-vulnerable/293076/3 "2021-12-31T17:15:41Z")

</div>

You may find your answer here ([[7.16] Upgrade to log4j 2.17.1 (#82111) by costin · Pull Request #82115 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/pull/82115)), it would be available with ES 7.16.3

---

<div class="post-metadata">

**Author:** ![Vashiru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vashiru/32/99623_2.png) [@Vashiru](https://discuss.elastic.co/u/Vashiru)\
**Post date:** [January 1, 2022, 11:17am UTC](https://discuss.elastic.co/t/log4j-cve-2021-44832-released-28th-dec-is-es-vulnerable/293076/4 "2022-01-01T11:17:51Z")

</div>

I saw that, but it doesn't really answer my question. I mean yes it's been updated, that could be for other reasons as well. It doesn't say anything about whether Elasticsearch is vulnerable or not.

---

<div class="post-metadata">

**Author:** ![Ram\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ram_n/32/97770_2.png) [@Ram\_N](https://discuss.elastic.co/u/Ram_N)\
**Post date:** [January 3, 2022, 4:53am UTC](https://discuss.elastic.co/t/log4j-cve-2021-44832-released-28th-dec-is-es-vulnerable/293076/5 "2022-01-03T04:53:21Z")

</div>

Im also in need of a clarification from Elasticsearch. Is ELK is vulnerable to this CVE?  
Can someone please clarify?

---

<div class="post-metadata">

**Author:** ![Ayush\_Mathur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayush_mathur/32/77134_2.png) [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Post date:** [January 3, 2022, 2:11pm UTC](https://discuss.elastic.co/t/log4j-cve-2021-44832-released-28th-dec-is-es-vulnerable/293076/6 "2022-01-03T14:11:37Z")

</div>

No, ES versions 6.8.9+ and 7.8+ are not affected by this as stated in community post:

> Supported versions of Elasticsearch (6.8.9+, 7.8+) used with recent versions of the JDK (JDK9+) are not susceptible to either remote code execution or information leakage. This is due to Elasticsearch’s usage of the Java Security Manager. Most other versions (5.6.11+, 6.4.0+ and 7.0.0+) can be protected via a simple JVM property change. The information leak vulnerability does not permit access to data within the Elasticsearch cluster. We have released Elasticsearch 7.16.1 and 6.8.21 which contain the JVM property by default and remove certain components of Log4j out of an abundance of caution. This is applicable to both CVE-2021-44228 and CVE-2021-45046. Elasticsearch has no known vulnerabilities to CVE-2021-45105.

> On December 19th we released 7.16.2 and 6.8.22 which include the most recent version of Log4j (2.17.0).

The full post can be found here: [Apache Log4j2 Remote Code Execution (RCE) Vulnerability](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476?ultron=log4js-exploit&blade=announcement&hulk=email&mkt_tok=ODEzLU1BTS0zOTIAAAGBUB4F7rmnRjhidRVncZkPXjgG2dNXrk44P5Ig-jzCVU0K4RdsQnyV4F7Iij07h_k7s1LExeTV_5I9DJf-iOYPpzm9ik-xQ_TXkhaBfaZ1JvnJUH6E)

---

<div class="post-metadata">

**Author:** ![Vashiru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vashiru/32/99623_2.png) [@Vashiru](https://discuss.elastic.co/u/Vashiru)\
**Post date:** [January 3, 2022, 2:33pm UTC](https://discuss.elastic.co/t/log4j-cve-2021-44832-released-28th-dec-is-es-vulnerable/293076/7 "2022-01-03T14:33:01Z")

</div>

That post unfortunately doesn't list the new CVE mentioned in this topic. It addresses all previous 3, but not this new 4th one.

---

<div class="post-metadata">

**Author:** ![Neil\_A\_Chikode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neil_a_chikode/32/99894_2.png) [@Neil\_A\_Chikode](https://discuss.elastic.co/u/Neil_A_Chikode)\
**Post date:** [January 5, 2022, 8:38pm UTC](https://discuss.elastic.co/t/log4j-cve-2021-44832-released-28th-dec-is-es-vulnerable/293076/8 "2022-01-05T20:38:41Z")

</div>

When will Elastic 7.16.3 with Log4j 2.17.1 be released?

---

<div class="post-metadata">

**Author:** ![Ayush\_Mathur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayush_mathur/32/77134_2.png) [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Post date:** [January 7, 2022, 5:16pm UTC](https://discuss.elastic.co/t/log4j-cve-2021-44832-released-28th-dec-is-es-vulnerable/293076/9 "2022-01-07T17:16:23Z")

</div>

As mentioned in the same link I provided earlier, 7.16.3 is targeted for 13th Jan.

[Apache Log4j2 Vulnerability - CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, CVE-2021-44832 - ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476?ultron=log4js-exploit&blade=announcement&hulk=email&mkt_tok=ODEzLU1BTS0zOTIAAAGBUB4F7rmnRjhidRVncZkPXjgG2dNXrk44P5Ig-jzCVU0K4RdsQnyV4F7Iij07h_k7s1LExeTV_5I9DJf-iOYPpzm9ik-xQ_TXkhaBfaZ1JvnJUH6E)

---

<div class="post-metadata">

**Author:** ![jeansalama](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeansalama/32/99721_2.png) [@jeansalama](https://discuss.elastic.co/u/jeansalama)\
**Post date:** [January 10, 2022, 9:04pm UTC](https://discuss.elastic.co/t/log4j-cve-2021-44832-released-28th-dec-is-es-vulnerable/293076/10 "2022-01-10T21:04:20Z")

</div>

[They said](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476#update-jan-6-4) that there is no known vulnerabilities :

> By default, Elasticsearch and Logstash have **no known vulnerabilities** to this as **relevant configuration files are only writable by cluster administrators**. We will release 7.16.3 and 6.8.23 to update Log4j to 2.17.1, targeting Jan 13.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2022, 9:05pm UTC](https://discuss.elastic.co/t/log4j-cve-2021-44832-released-28th-dec-is-es-vulnerable/293076/11 "2022-02-07T21:05:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
