# Zero-day-exploit in log4j2 which is part of elasticsearch

**URL:** <https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439>\
**Category:** Elasticsearch\
**Created:** [December 10, 2021, 3:46pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439 "2021-12-10T15:46:15Z")\
**Posts on this page:** 1\
**Showing post:** 25

<div class="post-metadata">

**Author:** ![Kami](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kami/32/98757_2.png) [@Kami](https://discuss.elastic.co/u/Kami)\
**Post date:** [December 11, 2021, 10:22pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/25 "2021-12-11T22:22:32Z")

</div>

I did some digging in and it appears that logstash plugins which depend on older version of **logstash-core-plugin-api** may also be affected, even when logstash is updated to include log4j v2.15.0.

It appears that logstash-core gem depends on an old vulnerable version of log4j as well - e.g. [logstash-core | RubyGems.org | your community gem host](https://rubygems.org/gems/logstash-core/versions/5.6.4-java).

Logstash plugins depend on **logstash-core-plugin-api** which depends on **logstash-core** so it's a transitive dependency of the plugin (and as such, gets pulled in when bundling all the dependencies for distribution). A lot of plugins bundle all the dependencies in the gems they push to RubyGems.

It appears that the latest version of logstash-core ([logstash-core | RubyGems.org | your community gem host](https://rubygems.org/gems/logstash-core/versions/7.5.2-java)) doesn't specify log4j as a dependency anymore (how does that work now? does it just use log4j bundled with logstash core?).

Can someone please double check and confirm my thinking? Thanks.

---

_[View the full topic](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439)._
