# Logstash-input-beats and logstash-input-http : log4j-api need upgraded \>= 2.8.2 as vulnerability CVE-2017-5645

**URL:** <https://discuss.elastic.co/t/logstash-input-beats-and-logstash-input-http-log4j-api-need-upgraded-2-8-2-as-vulnerability-cve-2017-5645/158284>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [November 27, 2018, 7:32am UTC](https://discuss.elastic.co/t/logstash-input-beats-and-logstash-input-http-log4j-api-need-upgraded-2-8-2-as-vulnerability-cve-2017-5645/158284 "2018-11-27T07:32:53Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![caixiangibm](https://avatars.discourse-cdn.com/v4/letter/c/9de0a6/32.png) [@caixiangibm](https://discuss.elastic.co/u/caixiangibm)\
**Post date:** [November 27, 2018, 7:32am UTC](https://discuss.elastic.co/t/logstash-input-beats-and-logstash-input-http-log4j-api-need-upgraded-2-8-2-as-vulnerability-cve-2017-5645/158284/1 "2018-11-27T07:32:53Z")

</div>

With upgrade logstash to v6.5, the plugin logstash-input-beats to 5.1.6 and logstash-input-http to 3.2.2, but the dependency of log4j-api still at version of "2.6.2", which is addressed in vulnerability CVE-2017-5645, and not match the vulnerability security check requirement.  
I had opened 2 PR to beats and http plugin github repos. Would the developers of logstash-input-beats and logstash-input-http check the dependencies and change the version of lo4j-api to 2.8.2 or beyond?

Check in logstash 6.5 -  
/usr/share/logstash# find . -name log4j-api\*

* * *

./vendor/bundle/jruby/2.3.0/gems/logstash-input-beats-5.1.6-java/vendor/jar-dependencies/org/apache/logging/log4j/log4j-api  
./vendor/bundle/jruby/2.3.0/gems/logstash-input-beats-5.1.6-java/vendor/jar-dependencies/org/apache/logging/log4j/log4j-api/2.6.2/log4j-api-2.6.2.jar  
./vendor/bundle/jruby/2.3.0/gems/logstash-input-http-3.2.2-java/vendor/jar-dependencies/org/apache/logging/log4j/log4j-api  
./vendor/bundle/jruby/2.3.0/gems/logstash-input-http-3.2.2-java/vendor/jar-dependencies/org/apache/logging/log4j/log4j-api/2.6.2/log4j-api-2.6.2.jar

I had opened 2 PR to beats and http plugin github repos.

> <https://github.com/logstash-plugins/logstash-input-beats/pull/351>

  

> <https://github.com/logstash-plugins/logstash-input-http/pull/99>

  
I aslo opened 2 issues to beats and http plugin githup repos.  

> <https://github.com/logstash-plugins/logstash-input-beats/issues/352>

  

> <https://github.com/logstash-plugins/logstash-input-http/issues/100>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2018, 7:40am UTC](https://discuss.elastic.co/t/logstash-input-beats-and-logstash-input-http-log4j-api-need-upgraded-2-8-2-as-vulnerability-cve-2017-5645/158284/2 "2018-12-25T07:40:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
