Zero-day-exploit in log4j2 which is part of elasticsearch

Yes. They are. Their advisory does mention it at the very top.

1 Like