# Log4j2 vulnerability mitigation - JndiLookup Removal

**URL:** https://discuss.elastic.co/t/log4j2-vulnerability-mitigation-jndilookup-removal/335356
**Category:** Logstash
**Created:** [June 6, 2023, 1:48pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation-jndilookup-removal/335356 "2023-06-06T13:48:57Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![JosephAnis](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@JosephAnis](https://discuss.elastic.co/u/JosephAnis)
#### Post date: [June 6, 2023, 1:48pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation-jndilookup-removal/335356/1 "2023-06-06T13:48:57Z")

</div>

Hi All,  
We are working on mitigating the Log4j2 vulnerability by removing the JndiLookup class as described here:

> [@Logstash 5.0.0-6.8.20 and 7.0.0-7.16.0: Log4j CVE-2021-44228, CVE-2021-45046 remediation](https://discuss.elastic.co/t/logstash-5-0-0-6-8-20-and-7-0-0-7-16-0-log4j-cve-2021-44228-cve-2021-45046-remediation/292343):
>
> Note — These instructions only apply if you are running Logstash 5.0.0 - 6.8.20, or 7.0.0 - 7.16.0. If you are running an older version of Logstash, or a version of Logstash \>= 6.8.21 in the 6.x series or \>= 7.16.1 in the 7.x series, these instructions do not apply. Please follow the guidance in [main announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476)Instructions for removing JndiLookup from relevant JAR files​ These instructions only apply to users running Logstash versions between 5.0.0 and 6.8.20 (inclusive) or between 7.0.0 a…

We are using version 7.9.2 for all ELK components and currently we can't upgrade to newer version.  
My question, is the JndiLookup being used by logstash ? Is there any impact expedted if it was removed or it is safe to remove it?  
Thanks a lot

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [June 6, 2023, 6:43pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation-jndilookup-removal/335356/2 "2023-06-06T18:43:49Z")

</div>

> [@JosephAnis](#):
>
> is the JndiLookup being used by logstash ?

Not unless _you_ have configured your log4j2.properties to contain a [JNDI lookup](https://logging.apache.org/log4j/2.x/manual/lookups.html#jndi-lookup). (This would be very unusual, and is definitely not something you could do by accident.)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 4, 2023, 6:44pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation-jndilookup-removal/335356/3 "2023-07-04T18:44:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
