# Urgent - Incomplete fix for Apache Log4j vulnerability v2.15.0

**URL:** https://discuss.elastic.co/t/urgent-incomplete-fix-for-apache-log4j-vulnerability-v2-15-0/291893
**Category:** Logstash
**Created:** [December 15, 2021, 3:59am UTC](https://discuss.elastic.co/t/urgent-incomplete-fix-for-apache-log4j-vulnerability-v2-15-0/291893 "2021-12-15T03:59:07Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![ppafford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppafford/32/36533_2.png) [@ppafford](https://discuss.elastic.co/u/ppafford)
#### Post date: [December 15, 2021, 3:59am UTC](https://discuss.elastic.co/t/urgent-incomplete-fix-for-apache-log4j-vulnerability-v2-15-0/291893/1 "2021-12-15T03:59:07Z")

</div>

Looks like there is another issue and another fix

> **[CVE-2021-45046 - GitHub Advisory Database](https://github.com/advisories/GHSA-7rjr-3q55-vv33)**
>
> Incomplete fix for Apache Log4j vulnerability

And the release of [Logstash 7.16.1 Release Notes | Logstash Reference [7.16] | Elastic](https://www.elastic.co/guide/en/logstash/current/logstash-7-16-1.html) has the incomplete fix.

When can this be addressed?

---

<div class="post-metadata">

### Author: ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)
#### Post date: [December 15, 2021, 4:08am UTC](https://discuss.elastic.co/t/urgent-incomplete-fix-for-apache-log4j-vulnerability-v2-15-0/291893/2 "2021-12-15T04:08:28Z")

</div>

Per the official [Security Announcement thread](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476):

> [@Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476/1):
>
> **[Update Dec 14th]** Log4j 2.16.0 has been released to address CVE-2021-45046. Logstash is not impacted by the vulnerability disclosed in CVE-2021-45046 because Logstash does not ship with logging layouts that can be exploited to trigger JNDI lookups through Thread Context references. **Elastic guidance remains to either remove the JndiLookup.class or upgrade Logstash to 7.16.1 or 6.8.21.**

---

<div class="post-metadata">

### Author: ![mp28may](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mp28may/32/39750_2.png) [@mp28may](https://discuss.elastic.co/u/mp28may)
#### Post date: [December 22, 2021, 4:58am UTC](https://discuss.elastic.co/t/urgent-incomplete-fix-for-apache-log4j-vulnerability-v2-15-0/291893/3 "2021-12-22T04:58:48Z")

</div>

Hi, I am currently using Elasticsearch and Logstash oss version 7.8.0.

The log4j-core and lo4j-api version in Elasticsearch is 2.11.1 and in Logstash it is 2.12.1.

Can i upgrade the log4j jar files (v.2.17.0) in my existing Elasticsearch and Logstash (7.8.0) to solve this vulnerability and without impacting the functioning of ELK.

Or it is necessary to upgrade to ELK v7.16.2 to solve it.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 19, 2022, 4:59am UTC](https://discuss.elastic.co/t/urgent-incomplete-fix-for-apache-log4j-vulnerability-v2-15-0/291893/4 "2022-01-19T04:59:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
