# Replace Log4j from 2.11.0 to 2.15.0

**URL:** https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901
**Category:** Logstash
**Created:** [December 15, 2021, 6:15am UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901 "2021-12-15T06:15:07Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![njain213](https://avatars.discourse-cdn.com/v4/letter/n/74df32/32.png) [@njain213](https://discuss.elastic.co/u/njain213)
#### Post date: [December 15, 2021, 6:15am UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901/1 "2021-12-15T06:15:07Z")

</div>

Hello Team,

I am using logstash 7.5.1 and having log4j jar as 2.11.1. Now as per doc [https://discuss.elastic.co/](https://discuss.elastic.co/) it is mentioned to remove JNDI class if we don't want to upgrade logstash. Is it possible if I can upgrade log4j jar to 2.15.0 in my current logstash version to mitigate this vulnerability? Do we have any impact if log4j jar will be different in logstash servers and elastic servers.

---

<div class="post-metadata">

### Author: ![mangesh\_shinde](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mangesh_shinde/32/93271_2.png) [@mangesh\_shinde](https://discuss.elastic.co/u/mangesh_shinde)
#### Post date: [December 15, 2021, 10:23am UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901/2 "2021-12-15T10:23:49Z")

</div>

I am also want solution for this. It's keep saying you might reinstall the gem  
How to do that?

---

<div class="post-metadata">

### Author: ![d71247](https://avatars.discourse-cdn.com/v4/letter/d/47e85d/32.png) [@d71247](https://discuss.elastic.co/u/d71247)
#### Post date: [December 15, 2021, 4:24pm UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901/3 "2021-12-15T16:24:09Z")

</div>

> [@Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476):
>
> Subject: Apache Log4j2 Vulnerability - CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, CVE-2021-44832 - ESA-2021-31 ​​Note - We will update this announcement with new details as they emerge from our analysis. Please check back periodically. Update Log Dec 16, 2021 - 04:20 UTC - Update Summary: ECK 1.9 released which automatically adds the JVM option to impacted Elasticsearch clusters managed by ECK. Dec 17, 2021 - 23:50 UTC - Update latest release of APM Java Agent to 1.28.2. Statement of pl…

---

<div class="post-metadata">

### Author: ![njain213](https://avatars.discourse-cdn.com/v4/letter/n/74df32/32.png) [@njain213](https://discuss.elastic.co/u/njain213)
#### Post date: [December 27, 2021, 7:33am UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901/4 "2021-12-27T07:33:47Z")

</div>

Hi Team,

As Log4j 2.17 is not vulnerable so if we don't want to go with upgrade, can we replace log4j jar from 2.11 to 2.17?

ELK current Version : 7.9.3

---

<div class="post-metadata">

### Author: ![njain213](https://avatars.discourse-cdn.com/v4/letter/n/74df32/32.png) [@njain213](https://discuss.elastic.co/u/njain213)
#### Post date: [December 27, 2021, 12:09pm UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901/5 "2021-12-27T12:09:18Z")

</div>

any update ?

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [December 27, 2021, 12:37pm UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901/6 "2021-12-27T12:37:08Z")

</div>

No, you can't just replace the jar with a newer version.

Please read the [security announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476/3) about the Log4J exploit, there you will find how to mitigate the issue according to your Logstash/Elasticsearch version.

If what you want to do is not mentioned there, then it is not recommended or testes by elastic.

---

<div class="post-metadata">

### Author: ![LokeshM](https://avatars.discourse-cdn.com/v4/letter/l/b3f665/32.png) [@LokeshM](https://discuss.elastic.co/u/LokeshM)
#### Post date: [January 5, 2022, 1:38am UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901/7 "2022-01-05T01:38:47Z")

</div>

Hi Team,  
We want to upgrade our current log4j 2.17.0 to 2.17.1. When will the log4j 2.17.1 release be available & Please provide us a release update

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [January 5, 2022, 1:44am UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901/8 "2022-01-05T01:44:13Z")

</div>

elastic have not announced a release date. I am sure that when a fix is available it will be noted in the top post in the [Security Announcements](https://discuss.elastic.co/c/announcements/security-announcements/31) thread.

---

<div class="post-metadata">

### Author: ![joseph-l.amalraj](https://avatars.discourse-cdn.com/v4/letter/j/da6949/32.png) [@joseph-l.amalraj](https://discuss.elastic.co/u/joseph-l.amalraj)
#### Post date: [January 6, 2022, 8:08am UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901/9 "2022-01-06T08:08:46Z")

</div>

Hi, We are using ELK 6.8.14. To upgrade the log4j to log4j 2.17. Could You please suggest me, what action we need to take.

Thank You.

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [January 6, 2022, 9:01am UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901/10 "2022-01-06T09:01:31Z")

</div>

Per the [announcement here](https://ela.st/log4j)

> **our overall recommendation is to update to version 7.16.2 or 6.8.22.**

If you want Log4j 2.17 you should upgrade Elasticsearch to 6.8.22  
There is no other supported option.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 3, 2022, 9:02am UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901/11 "2022-02-03T09:02:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
