# Log4j2 vulnerability mitigation

**URL:** https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213
**Category:** Logstash
**Created:** [June 5, 2023, 12:09pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213 "2023-06-05T12:09:36Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![mostafaelsayed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mostafaelsayed/32/82057_2.png) [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)
#### Post date: [June 5, 2023, 12:09pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213/1 "2023-06-05T12:09:36Z")

</div>

Hello all,

I was checking the actions needed from our side in the ELK cluster to mitigate the Log4j2 vulnerability found in Dec 2021. we are using 7.9.2 for all ELK components. After investigating and checking the below links:  
[Introducing 7.16.2 and 6.8.22 releases of Elasticsearch and Logstash to upgrade Apache Log4j2](https://www.elastic.co/blog/new-elasticsearch-and-logstash-releases-upgrade-apache-log4j2?utm_source=log4j+hub+blog&utm_medium=embed+link&utm_campaign=log4j_hub_blog&utm_id=log4j&utm_content=elasticsearch+logstash+update)

[Apache Log4j2 Remote Code Execution (RCE) Vulnerability](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476?ultron=log4js-exploit&blade=announcement&hulk=email&mkt_tok=ODEzLU1BTS0zOTIAAAGBU8N1ZUOwzTcRbJCOiByHmeYiopMnarq-QPWBIyhPI3Vvsp6w-4q4PBbTGZ3fZ0sB75cpaUdOddA1k-6-yh3QwAicvJTgafdJWv_-9Cn2GoKLvsmt&utm_source=log4j+hub+blog&utm_medium=embed+link&utm_campaign=log4j_hub_blog&utm_id=log4j&utm_content=log4j2+advisory)

[Logstash 5.0.0-6.8.20 and 7.0.0-7.16.0: Log4j CVE-2021-44228, CVE-2021-45046 remediation](https://discuss.elastic.co/t/logstash-5-0-0-6-8-20-and-7-0-0-7-16-0-log4j-cve-2021-44228-cve-2021-45046-remediation/292343)

There are 3 vulnerability issues logged  
CVE-2021-44228  
CVE-2021-45046  
CVE-2021-45105

I concluded that elasticsearch won't be affected by CVE-2021-44228 and CVE-2021-45046 but there is no mention of CVE-2021-45105

for logstash, there will be Information Leakage and will be mitigated through script that will solve CVE-2021-44228 and CVE-2021-45046 but again, there is no mention of CVE-2021-45105

My questions

1. what is the minimum effort needed to mitigate all the 3 vulnerabilities? do we need additional mitigation script or something for elasticsearch and logstash to solve CVE-2021-45105 or we won't need that?

2. can we upgrade only log4j2 to version 2.17.1 or this is not an option?

Thanks

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [June 5, 2023, 12:40pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213/3 "2023-06-05T12:40:17Z")

</div>

The forum [post](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476?ultron=log4js-exploit&blade=announcement&hulk=email&mkt_tok=ODEzLU1BTS0zOTIAAAGBU8N1ZUOwzTcRbJCOiByHmeYiopMnarq-QPWBIyhPI3Vvsp6w-4q4PBbTGZ3fZ0sB75cpaUdOddA1k-6-yh3QwAicvJTgafdJWv_-9Cn2GoKLvsmt&utm_source=log4j+hub+blog&utm_medium=embed+link&utm_campaign=log4j_hub_blog&utm_id=log4j&utm_content=log4j2+advisory) about log4j vulnerabilites that you shared has all the information you need.

It mentions `CVE-2021-45105` many times saying that both Logstash and Elasticsearch are not vulnerable to it.

> Dec 18, 2021 - 23:40 UTC - Added statement that Elasticsearch, Logstash, and APM Java agent have **no known vulnerabilities** to **CVE-2021-45105**

> [@mostafaelsayed](#):
>
> what is the minimum effort needed to mitigate all the 3 vulnerabilities?

The version you are using reached EOL and it is not supported any more, you need to update to the last version in the version 7 branch which is `7.17.10`.

Check the breaking changed between your version and the last one and plan your upgrade.

> [@mostafaelsayed](#):
>
> can we upgrade only log4j2 to version 2.17.1 or this is not an option?

No, not possible, you cannot upgrade just the log4j library, you need to upgrade the entire tool.

---

<div class="post-metadata">

### Author: ![mostafaelsayed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mostafaelsayed/32/82057_2.png) [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)
#### Post date: [June 5, 2023, 1:16pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213/4 "2023-06-05T13:16:25Z")

</div>

Thanks @leandrojmp

for the EOL issue, I am using 7.9.2, not 5.0.0. This version also reached EOL?

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [June 5, 2023, 1:23pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213/5 "2023-06-05T13:23:51Z")

</div>

> [@mostafaelsayed](#):
>
> This version also reached EOL?

Yes, from the version 7 branch, only 7.17.X is still maintained and supported.

You should upgrade to `7.17.10` and after that plan an upgrade to `8.8`.

---

<div class="post-metadata">

### Author: ![mostafaelsayed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mostafaelsayed/32/82057_2.png) [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)
#### Post date: [June 5, 2023, 2:52pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213/6 "2023-06-05T14:52:54Z")

</div>

Thanks @leandrojmp

just last question

if the upgrade can't be done now, the only option is using the procedure mentioned to remove JndiLookup class to mitigate logstash? elasticsearch already does not have any mitigation procedure needed

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [June 5, 2023, 3:27pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213/7 "2023-06-05T15:27:11Z")

</div>

> [@mostafaelsayed](#):
>
> if the upgrade can't be done now, the only option is using the procedure mentioned to remove JndiLookup class to mitigate logstash?

Everything related to Log4j and any Elastic Tool is already answered in the second link you shared.

If you can't upgrade the only option is to use the procedure indicated on that link.

---

<div class="post-metadata">

### Author: ![mostafaelsayed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mostafaelsayed/32/82057_2.png) [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)
#### Post date: [June 5, 2023, 3:33pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213/8 "2023-06-05T15:33:18Z")

</div>

Thanks

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 3, 2023, 3:33pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213/9 "2023-07-03T15:33:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
