# Log4j vulnerability and Elasticsearch 6.8.21

**URL:** https://discuss.elastic.co/t/log4j-vulnerability-and-elasticsearch-6-8-21/292088
**Category:** Elasticsearch
**Created:** [December 16, 2021, 6:59am UTC](https://discuss.elastic.co/t/log4j-vulnerability-and-elasticsearch-6-8-21/292088 "2021-12-16T06:59:21Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![srikanth.puli](https://avatars.discourse-cdn.com/v4/letter/s/5f9b8f/32.png) [@srikanth.puli](https://discuss.elastic.co/u/srikanth.puli)
#### Post date: [December 16, 2021, 6:59am UTC](https://discuss.elastic.co/t/log4j-vulnerability-and-elasticsearch-6-8-21/292088/1 "2021-12-16T06:59:21Z")

</div>

Hi,  
As per the release notes of Elasticserch 6.8.21, the vulnerability [CVE-2021-44228](https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-44228) is addressed by removing the class file JndiLookup.class from the log4j jar. We have upgraded our application with Elasticsearch 6.8.21 and I see the class file is removed from log4j jar. However I found another JndiLookup.class in the jar file Elasticsearch-sql-cli-6.8.21.jar?  
doesn't it make the vulnerability alive?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 13, 2022, 7:00am UTC](https://discuss.elastic.co/t/log4j-vulnerability-and-elasticsearch-6-8-21/292088/2 "2022-01-13T07:00:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
