# Urgent - Incomplete fix for Apache Log4j vulnerability v2.15.0

**URL:** https://discuss.elastic.co/t/urgent-incomplete-fix-for-apache-log4j-vulnerability-v2-15-0/291893
**Category:** Logstash
**Created:** [December 15, 2021, 3:59am UTC](https://discuss.elastic.co/t/urgent-incomplete-fix-for-apache-log4j-vulnerability-v2-15-0/291893 "2021-12-15T03:59:07Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)
#### Post date: [December 15, 2021, 4:08am UTC](https://discuss.elastic.co/t/urgent-incomplete-fix-for-apache-log4j-vulnerability-v2-15-0/291893/2 "2021-12-15T04:08:28Z")

</div>

Per the official [Security Announcement thread](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476):

> [@Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476/1):
>
> **[Update Dec 14th]** Log4j 2.16.0 has been released to address CVE-2021-45046. Logstash is not impacted by the vulnerability disclosed in CVE-2021-45046 because Logstash does not ship with logging layouts that can be exploited to trigger JNDI lookups through Thread Context references. **Elastic guidance remains to either remove the JndiLookup.class or upgrade Logstash to 7.16.1 or 6.8.21.**

---

_[View the full topic](https://discuss.elastic.co/t/urgent-incomplete-fix-for-apache-log4j-vulnerability-v2-15-0/291893)._
