# Zero-day-exploit in log4j2 which is part of elasticsearch

**URL:** https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439
**Category:** Elasticsearch
**Created:** [December 10, 2021, 3:46pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439 "2021-12-10T15:46:15Z")
**Posts on this page:** 1
**Showing post:** 56

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [December 14, 2021, 3:09pm UTC](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/56 "2021-12-14T15:09:12Z")

</div>

> [@begin](#):
>
> Why is v7.7 affected while v7.8 is not?

I think you're misinterpreting the [announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476) which says:

> Supported versions of Elasticsearch (6.8.9+, 7.8+) used with recent versions of the JDK (JDK9+) are not susceptible to either remote code execution or information leakage.

It doesn't say that 7.7 is affected, just that it's not a supported version (i.e. it's [past EOL](https://www.elastic.co/support/eol)) so it's out of scope.

2021-12-16 edit to add: "out of scope" meaning "out of the scope of this particular sentence". There are other parts of the announcement that relate to EOL versions.

---

_[View the full topic](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439)._
