# Log4j on Elasticsearch 7.9.2

**URL:** https://discuss.elastic.co/t/log4j-on-elasticsearch-7-9-2/292093
**Category:** Elasticsearch
**Created:** [December 16, 2021, 7:32am UTC](https://discuss.elastic.co/t/log4j-on-elasticsearch-7-9-2/292093 "2021-12-16T07:32:03Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![h4h3hj](https://avatars.discourse-cdn.com/v4/letter/h/4af34b/32.png) [@h4h3hj](https://discuss.elastic.co/u/h4h3hj)
#### Post date: [December 16, 2021, 7:32am UTC](https://discuss.elastic.co/t/log4j-on-elasticsearch-7-9-2/292093/1 "2021-12-16T07:32:03Z")

</div>

Hi Everyone,

As we know the vulnerability (CVE-2021-44228) impacts multiple versions of the Apache Log4j2

I can see Elastic has updated about this  
Supported versions of Elasticsearch (6.8.9+, 7.8+) used with recent versions of the JDK (JDK9+) are not susceptible to either remote code execution or information leakage. This is due to Elasticsearch’s usage of the Java Security Manager. Most other versions (5.6.11+, 6.4.0+ and 7.0.0+) can be protected via a simple JVM property change. The information leak vulnerability does not permit access to data within the Elasticsearch cluster. We have released Elasticsearch 7.16.1 and 6.8.21 which contain the JVM property by default and remove certain components of Log4j out of an abundance of caution.

Currently, I'm having Elasticsearch version 7.9.2 on production server, but I found a lot of packages log4j 2.11.1.jar under elastic (the impact version between 2.0 and 2.14.1)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/b/4b8afdc0805748a20898894e919543059f1970c2.png)

So, should I worry about it? and consider an upgrade to higher elastic version, i.e 7.16?  
or can I safely ignore those ones?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [December 20, 2021, 12:08am UTC](https://discuss.elastic.co/t/log4j-on-elasticsearch-7-9-2/292093/2 "2021-12-20T00:08:03Z")

</div>

Welcome to our community! 😃

You should definitely upgrade as a matter of general maintenance. However we will be releasing a new version with upgraded packages very soon.

---

<div class="post-metadata">

### Author: ![h4h3hj](https://avatars.discourse-cdn.com/v4/letter/h/4af34b/32.png) [@h4h3hj](https://discuss.elastic.co/u/h4h3hj)
#### Post date: [December 20, 2021, 2:35am UTC](https://discuss.elastic.co/t/log4j-on-elasticsearch-7-9-2/292093/3 "2021-12-20T02:35:56Z")

</div>

Thank you very much,  
so, should I wait for the new version to be released, or which version can I upgrade to for now?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [December 20, 2021, 2:38am UTC](https://discuss.elastic.co/t/log4j-on-elasticsearch-7-9-2/292093/4 "2021-12-20T02:38:35Z")

</div>

Upgrading to 7.16.2 will also upgrade the log4j package to the latest without the flaw(s).

---

<div class="post-metadata">

### Author: ![h4h3hj](https://avatars.discourse-cdn.com/v4/letter/h/4af34b/32.png) [@h4h3hj](https://discuss.elastic.co/u/h4h3hj)
#### Post date: [December 20, 2021, 3:04am UTC](https://discuss.elastic.co/t/log4j-on-elasticsearch-7-9-2/292093/5 "2021-12-20T03:04:16Z")

</div>

Thank you very much, I really appreciate it 🙂

---

<div class="post-metadata">

### Author: ![h4klm](https://avatars.discourse-cdn.com/v4/letter/h/bbce88/32.png) [@h4klm](https://discuss.elastic.co/u/h4klm)
#### Post date: [January 16, 2022, 10:31pm UTC](https://discuss.elastic.co/t/log4j-on-elasticsearch-7-9-2/292093/6 "2022-01-16T22:31:55Z")

</div>

Hello Guys currently log4j version 2.11 both core and api  
what about remove those jars and replace them with  
[https://repo1.maven.org/maven2/org/apache/logging/log4j/log4j-api/2.17.0/](https://repo1.maven.org/maven2/org/apache/logging/log4j/log4j-api/2.17.0/)  
[https://repo1.maven.org/maven2/org/apache/logging/log4j/log4j-core/2.17.0/](https://repo1.maven.org/maven2/org/apache/logging/log4j/log4j-core/2.17.0/)  
and restart Elasticsearch service it's working but i don't know if this will fix the vulnerability or even worth impact the data could you please advice

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [January 17, 2022, 2:21am UTC](https://discuss.elastic.co/t/log4j-on-elasticsearch-7-9-2/292093/7 "2022-01-17T02:21:00Z")

</div>

We do not recommend replacing jar files within an existing Elasticsearch install.

Please set [Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31 - Security Announcements - Discuss the Elastic Stack](https://ela.st/log4j) for advice on how to address this issue.

---

<div class="post-metadata">

### Author: ![h4klm](https://avatars.discourse-cdn.com/v4/letter/h/bbce88/32.png) [@h4klm](https://discuss.elastic.co/u/h4klm)
#### Post date: [January 17, 2022, 12:07pm UTC](https://discuss.elastic.co/t/log4j-on-elasticsearch-7-9-2/292093/8 "2022-01-17T12:07:50Z")

</div>

upgrading live system not recommended on my cause right now can i apply this replacement jars till we manage the upgrade plan what do you think

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [January 17, 2022, 12:33pm UTC](https://discuss.elastic.co/t/log4j-on-elasticsearch-7-9-2/292093/9 "2022-01-17T12:33:12Z")

</div>

My answer is the same as last time you asked.

We do not recommend replacing jar files within an existing Elasticsearch install.

Please follow the official advice on how to address this issue.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 14, 2022, 12:33pm UTC](https://discuss.elastic.co/t/log4j-on-elasticsearch-7-9-2/292093/10 "2022-02-14T12:33:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
