# Under what circumstances can log4j be used to exploit Logstash?

**URL:** https://discuss.elastic.co/t/under-what-circumstances-can-log4j-be-used-to-exploit-logstash/291886
**Category:** Logstash
**Created:** [December 15, 2021, 2:34am UTC](https://discuss.elastic.co/t/under-what-circumstances-can-log4j-be-used-to-exploit-logstash/291886 "2021-12-15T02:34:06Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)
#### Post date: [December 15, 2021, 4:26am UTC](https://discuss.elastic.co/t/under-what-circumstances-can-log4j-be-used-to-exploit-logstash/291886/2 "2021-12-15T04:26:05Z")

</div>

> [@Sjaak01](#):
>
> Under what circumstances can the log4j bug be exploited in Logstash?

A carefully-crafted payload that is _processed_ by Logstash and results in a message being sent to the logger containing that payload, is sufficient to trigger the issue. The payload does not have to be transmitted directly by an attacker, but could be fetched by any one of a pipeline's input plugins so long as doing so resulted in the exploit string being included in a log message.

The _only_ validated mitigations remain the removal of the class file or upgrading to a patched release.

> [@Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476/1):
>
> **Elastic guidance remains to either remove the JndiLookup.class or upgrade Logstash to 7.16.1 or 6.8.21.**

---

_[View the full topic](https://discuss.elastic.co/t/under-what-circumstances-can-log4j-be-used-to-exploit-logstash/291886)._
