# Log4j security vulnerability and plugins which bundle / vendor dependencies

**URL:** <https://discuss.elastic.co/t/log4j-security-vulnerability-and-plugins-which-bundle-vendor-dependencies/291537>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [December 12, 2021, 10:54am UTC](https://discuss.elastic.co/t/log4j-security-vulnerability-and-plugins-which-bundle-vendor-dependencies/291537 "2021-12-12T10:54:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kami](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kami/32/98757_2.png) [@Kami](https://discuss.elastic.co/u/Kami)\
**Post date:** [December 12, 2021, 10:54am UTC](https://discuss.elastic.co/t/log4j-security-vulnerability-and-plugins-which-bundle-vendor-dependencies/291537/1 "2021-12-12T10:54:34Z")

</div>

(this post has been moved from [Zero-day-exploit in log4j2 which is part of elasticsearch - #25 by Kami](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/25))

Dear logstash community,

I would like to better understand on how log4j vulnerability affects logstash plugins which bundle / vendor their dependencies.

When auditing a logstash installation, I noticed multiple log4j jars bundled with various plugins:

```auto
find /opt/logstash/ -name "log4j*.jar"
/opt/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-http-3.4.2-java/vendor/jar-dependencies/org/apache/logging/log4j/log4j-api/2.11.1/log4j-api-2.11.1.jar
/opt/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-beats-6.2.1-java/vendor/jar-dependencies/org/apache/logging/log4j/log4j-api/2.11.1/log4j-api-2.11.1.jar
/opt/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-azure_event_hubs-1.4.0/vendor/jar-dependencies/org/apache/logging/log4j/log4j-slf4j-impl/2.9.1/log4j-slf4j-impl-2.9.1.jar
/opt/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-azure_event_hubs-1.4.0/vendor/jar-dependencies/org/apache/logging/log4j/log4j-api/2.9.1/log4j-api-2.9.1.jar
/opt/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-test-0.2.0/vendor/bundle/jruby/2.5.0/gems/logstash-core-5.6.4-java/lib/org/apache/logging/log4j/log4j-slf4j-impl/2.6.2/log4j-slf4j-impl-2.6.2.jar
/opt/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-test-0.2.0/vendor/bundle/jruby/2.5.0/gems/logstash-core-5.6.4-java/lib/org/apache/logging/log4j/log4j-api/2.6.2/log4j-api-2.6.2.jar
/opt/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-test-0.2.0/vendor/bundle/jruby/2.5.0/gems/logstash-core-5.6.4-java/lib/org/apache/logging/log4j/log4j-core/2.6.2/log4j-core-2.6.2.jar
/opt/logstash/logstash-core/lib/jars/log4j-slf4j-impl-2.14.0.jar
/opt/logstash/logstash-core/lib/jars/log4j-api-2.14.0.jar
/opt/logstash/logstash-core/lib/jars/log4j-core-2.14.0.jar
/opt/logstash/logstash-core/lib/jars/log4j-1.2-api-2.14.0.jar
/opt/logstash/logstash-core/lib/jars/log4j-jcl-2.14.0.jar

```

After digging in further, I noticed that some logstash plugins bundle / vendor all of their dependencies in the RubyGem they publish (I assume that's done to make installations in airgap environments easier and / or similar).

After checking the gem metadata it shows that logstash plugin depends on **logstash-core-plugin-api** which depends on **logstash-core** which depends on log4j (so logstash-core is a transitive dependency of the plugin).

It appears that a lot of plugins transitively depend on older version of logstash-core which still requires log4j ([logstash-core | RubyGems.org | your community gem host](https://rubygems.org/gems/logstash-core/versions/5.6.4-java)).

Newer versions of logstash-core don't seem to depend on it anymore ([logstash-core | RubyGems.org | your community gem host](https://rubygems.org/gems/logstash-core/versions/7.5.2-java) - i assume they use log4j bundled in the logstash core, but dunno).

I would like to better understand if this is an indeed an issue and how to handle that in the problematic plugins - can we bump minimum version of logstash-plugin-core (and as such, logstash-core) or will this cause issues with logstash version compatibility? Or simply the best solution is not to bundle / vendor dependencies with the gem?

Thanks.

---

<div class="post-metadata">

**Author:** ![lucas\_weka](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lucas_weka/32/98994_2.png) [@lucas\_weka](https://discuss.elastic.co/u/lucas_weka)\
**Post date:** [December 15, 2021, 9:40am UTC](https://discuss.elastic.co/t/log4j-security-vulnerability-and-plugins-which-bundle-vendor-dependencies/291537/2 "2021-12-15T09:40:24Z")

</div>

We used [GitHub - mergebase/log4j-detector: Detects log4j versions on your file-system, including deeply recursively nested copies (zips inside zips inside zips).](https://github.com/mergebase/log4j-detector) to scan logstash and found:

`/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-tcp-6.0.3-java/vendor/jar-dependencies/org/logstash/inputs/logstash-input-tcp/6.0.3/logstash-input-tcp-6.0.3.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(`

I'm not sure how this is used by logstash, but I removed the `JndiLookup.class` from that JAR for now. Maybe someone can clearify that.

---

<div class="post-metadata">

**Author:** ![kakoni](https://avatars.discourse-cdn.com/v4/letter/k/8c91f0/32.png) [@kakoni](https://discuss.elastic.co/u/kakoni)\
**Post date:** [December 16, 2021, 7:59am UTC](https://discuss.elastic.co/t/log4j-security-vulnerability-and-plugins-which-bundle-vendor-dependencies/291537/3 "2021-12-16T07:59:34Z")

</div>

Typical logstash distributions (rpm, deb, docker ..) come with  
logstash-input-azure\_event\_hubs, logstash-input-beats and logstash-input-http plugins, which all have dependency to log4j-api, but not log4j-core. As per current knowledge, log4j-api is not vulnerable.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [December 16, 2021, 3:47pm UTC](https://discuss.elastic.co/t/log4j-security-vulnerability-and-plugins-which-bundle-vendor-dependencies/291537/4 "2021-12-16T15:47:05Z")

</div>

This is addressed in the [ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476) security announcement.

More details:

- Most plugins rely on log4j-api, which allows the plugins to use log4j provided by the application without providing their own. The log4j-api is not vulnerable to the CVE.
- 7.16.1 and 6.8.21 provide log4j-core 2.15, and also both still include an old, _unreachable_ log4j-core in one of their bundled plugins (TCP input).
- The jar is unreachable (and therefore not exploitable) because of how plugins are loaded in Logstash, but removing its JNDI lookup class is a safe mechanism to add peace of mind
- updated versions of the TCP Input have been released to rely only on log4j-api and will be included in any subsequent patch releases.

---

<div class="post-metadata">

**Author:** ![Kami](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kami/32/98757_2.png) [@Kami](https://discuss.elastic.co/u/Kami)\
**Post date:** [December 16, 2021, 4:02pm UTC](https://discuss.elastic.co/t/log4j-security-vulnerability-and-plugins-which-bundle-vendor-dependencies/291537/5 "2021-12-16T16:02:59Z")

</div>

Thanks for the clarification.

This addresses all the concerns I had.

My main concern was with "The jar is unreachable (and therefore not exploitable) because of how plugins are loaded in Logstash, but removing its JNDI lookup class is a safe mechanism to add peace of mind".

I didn't dig through the plugin loading code so I wasn't sure if that bundled jar was actually being used or not, but now you clarified it's not being used.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 13, 2022, 4:03pm UTC](https://discuss.elastic.co/t/log4j-security-vulnerability-and-plugins-which-bundle-vendor-dependencies/291537/6 "2022-01-13T16:03:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
