# Replace Log4j from 2.x to 2.17.0 or later

**URL:** https://discuss.elastic.co/t/replace-log4j-from-2-x-to-2-17-0-or-later/292897
**Category:** Elasticsearch
**Created:** [December 24, 2021, 1:28pm UTC](https://discuss.elastic.co/t/replace-log4j-from-2-x-to-2-17-0-or-later/292897 "2021-12-24T13:28:07Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [December 24, 2021, 2:17pm UTC](https://discuss.elastic.co/t/replace-log4j-from-2-x-to-2-17-0-or-later/292897/2 "2021-12-24T14:17:14Z")

</div>

No, you can't just replace de library for a newer version.

All the recommendations regarding the Log4shell exploit are in the pinned [security announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476), there you will find instructions to mitigate this in different versions.

---

_[View the full topic](https://discuss.elastic.co/t/replace-log4j-from-2-x-to-2-17-0-or-later/292897)._
