# Logstash update log4j version

**URL:** https://discuss.elastic.co/t/logstash-update-log4j-version/291946
**Category:** Logstash
**Created:** [December 15, 2021, 10:34am UTC](https://discuss.elastic.co/t/logstash-update-log4j-version/291946 "2021-12-15T10:34:55Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)
#### Post date: [December 15, 2021, 9:43pm UTC](https://discuss.elastic.co/t/logstash-update-log4j-version/291946/2 "2021-12-15T21:43:02Z")

</div>

The packaged code is still attempting to load the old jars, and is not finding them.

While upgrading the log4j jars and replacing all references in-place _may_ work from a technical standpoint, the recommended mitigations per [ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476) remain:

> [@Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476/1):
>
> Users should upgrade to Logstash [7.16.2](https://www.elastic.co/downloads/logstash) or [6.8.22](https://elastic.co/downloads/past-releases/logstash-6-8-22), which were released on December 19, 2021. These releases replace vulnerable versions of Log4j with Log4j 2.17.0.
> 
> The widespread flag -Dlog4j2.formatMsgNoLookups=true is NOT sufficient to mitigate the vulnerability in Logstash in all cases, as Logstash uses Log4j in a way where the flag has no effect. If the user cannot upgrade to Logstash 7.16.2 or 6.8.22, it is necessary to remove the JndiLookup class from the log4j2 core jar, with the following command (which is applicable for 5.x, 6.x, and 7.x):

[EDIT: updated with guidance from 2021-12-19 reflecting releases of 7.16.2 and 6.8.22]

---

_[View the full topic](https://discuss.elastic.co/t/logstash-update-log4j-version/291946)._
