# When will the next patch be released for Elasticsearch

**URL:** <https://discuss.elastic.co/t/when-will-the-next-patch-be-released-for-elasticsearch/292066>\
**Category:** Elasticsearch\
**Created:** [December 16, 2021, 2:49am UTC](https://discuss.elastic.co/t/when-will-the-next-patch-be-released-for-elasticsearch/292066 "2021-12-16T02:49:52Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aydan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aydan/32/141998_2.png) [@Aydan](https://discuss.elastic.co/u/Aydan)\
**Post date:** [December 16, 2021, 2:49am UTC](https://discuss.elastic.co/t/when-will-the-next-patch-be-released-for-elasticsearch/292066/1 "2021-12-16T02:49:52Z")

</div>

When will be the next patch for Elasticsearch?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 16, 2021, 3:33am UTC](https://discuss.elastic.co/t/when-will-the-next-patch-be-released-for-elasticsearch/292066/2 "2021-12-16T03:33:40Z")

</div>

Per Announcement Here which is being updated daily so please check back there

> [@Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476):
>
> Subject: Apache Log4j2 Vulnerability - CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, CVE-2021-44832 - ESA-2021-31 ​​Note - We will update this announcement with new details as they emerge from our analysis. Please check back periodically. Update Log Dec 16, 2021 - 04:20 UTC - Update Summary: ECK 1.9 released which automatically adds the JVM option to impacted Elasticsearch clusters managed by ECK. Dec 17, 2021 - 23:50 UTC - Update latest release of APM Java Agent to 1.28.2. Statement of pl…

> As of December 13, 2021, we have released Elasticsearch 6.8.21 and 7.16.1 which set the JVM option identified below and remove the vulnerable JndiLookup class from Log4j out of an abundance of caution. If you are on a 6.x version prior to 6.4.0 and upgrading is not possible, you can follow [the instructions here](https://discuss.elastic.co/t/elasticsearch-5-0-0-5-6-10-and-6-0-0-6-3-2-log4j-cve-2021-44228-cve-2021-45046-remediation/292054).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 20, 2021, 12:08am UTC](https://discuss.elastic.co/t/when-will-the-next-patch-be-released-for-elasticsearch/292066/3 "2021-12-20T00:08:42Z")

</div>

Welcome to our community! 😃

Very soon, we don;'t provide dates or specific ETAs though sorry.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 20, 2021, 12:51am UTC](https://discuss.elastic.co/t/when-will-the-next-patch-be-released-for-elasticsearch/292066/4 "2021-12-20T00:51:44Z")

</div>

@Aydan If you are looking for 7.16.2 for the Log4J see here

> **[Introducing 7.16.2 and 6.8.22 releases of Elasticsearch and Logstash to...](https://www.elastic.co/blog/new-elasticsearch-and-logstash-releases-upgrade-apache-log4j2)**
>
> We are pleased to announce new versions of Elasticsearch and Logstash, 7.16.2 and 6.8.22, to upgrade to the latest release of Apache Log4j and address false positive concerns with some vulnerability scanners.

It is also at the very top of this page..

> ## Update Log
> 
> ....
> 
> - Dec 19, 2021 - 13:32 UTC - [Elastiscsearch](https://www.elastic.co/downloads/elasticsearch) and [Logstash](https://www.elastic.co/downloads/logstash) 7.16.2 and 6.8.22 are now released. These releases include the most recent version of Log4j (2.17.0).

---

<div class="post-metadata">

**Author:** ![Aydan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aydan/32/141998_2.png) [@Aydan](https://discuss.elastic.co/u/Aydan)\
**Post date:** [December 20, 2021, 3:30am UTC](https://discuss.elastic.co/t/when-will-the-next-patch-be-released-for-elasticsearch/292066/5 "2021-12-20T03:30:08Z")

</div>

Thank You

---

<div class="post-metadata">

**Author:** ![Aydan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aydan/32/141998_2.png) [@Aydan](https://discuss.elastic.co/u/Aydan)\
**Post date:** [December 20, 2021, 3:31am UTC](https://discuss.elastic.co/t/when-will-the-next-patch-be-released-for-elasticsearch/292066/6 "2021-12-20T03:31:04Z")

</div>

Thank you

---

<div class="post-metadata">

**Author:** ![Aydan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aydan/32/141998_2.png) [@Aydan](https://discuss.elastic.co/u/Aydan)\
**Post date:** [December 20, 2021, 3:37am UTC](https://discuss.elastic.co/t/when-will-the-next-patch-be-released-for-elasticsearch/292066/7 "2021-12-20T03:37:57Z")

</div>

I have a concern regarding Elasticsearch.

In you announcement, it is stated that to mitigate the vulnerability, the -Dlog4j2.formatMsgNoLookups=true variable to the jvm.options.

However, reading the below article states that this is an insufficient mitigation measure:

[https://logging.apache.org/log4j/2.x/security.html#CVE-2021-45105](https://logging.apache.org/log4j/2.x/security.html#CVE-2021-45105)

Are you able to confirm if this?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 20, 2021, 3:41am UTC](https://discuss.elastic.co/t/when-will-the-next-patch-be-released-for-elasticsearch/292066/8 "2021-12-20T03:41:03Z")

</div>

Please see [Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476) as it goes into all of this in detail 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2022, 3:41am UTC](https://discuss.elastic.co/t/when-will-the-next-patch-be-released-for-elasticsearch/292066/9 "2022-01-17T03:41:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
