# Log4j2 vulnerability mitigation

**URL:** https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213
**Category:** Logstash
**Created:** [June 5, 2023, 12:09pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213 "2023-06-05T12:09:36Z")
**Posts on this page:** 1
**Showing post:** 3

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [June 5, 2023, 12:40pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213/3 "2023-06-05T12:40:17Z")

</div>

The forum [post](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476?ultron=log4js-exploit&blade=announcement&hulk=email&mkt_tok=ODEzLU1BTS0zOTIAAAGBU8N1ZUOwzTcRbJCOiByHmeYiopMnarq-QPWBIyhPI3Vvsp6w-4q4PBbTGZ3fZ0sB75cpaUdOddA1k-6-yh3QwAicvJTgafdJWv_-9Cn2GoKLvsmt&utm_source=log4j+hub+blog&utm_medium=embed+link&utm_campaign=log4j_hub_blog&utm_id=log4j&utm_content=log4j2+advisory) about log4j vulnerabilites that you shared has all the information you need.

It mentions `CVE-2021-45105` many times saying that both Logstash and Elasticsearch are not vulnerable to it.

> Dec 18, 2021 - 23:40 UTC - Added statement that Elasticsearch, Logstash, and APM Java agent have **no known vulnerabilities** to **CVE-2021-45105**

> [@mostafaelsayed](#):
>
> what is the minimum effort needed to mitigate all the 3 vulnerabilities?

The version you are using reached EOL and it is not supported any more, you need to update to the last version in the version 7 branch which is `7.17.10`.

Check the breaking changed between your version and the last one and plan your upgrade.

> [@mostafaelsayed](#):
>
> can we upgrade only log4j2 to version 2.17.1 or this is not an option?

No, not possible, you cannot upgrade just the log4j library, you need to upgrade the entire tool.

---

_[View the full topic](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213)._
