Zero-day-exploit in log4j2 which is part of elasticsearch

Base on the affected version of the announcement, would like to confirm actually nothing need to do if

  1. Elasticsearch version is 7.2+ with bundled JDK11+
  2. logstash 7.X with JDK 11.0.1+

is it correct?

2 Likes