Skip to content

0-day in log4j package #81620

@aSapien

Description

@aSapien

Hi Elastic,

A 0-day exploit in log4j package has been published and it looks like ElasticSearch could be affected by a vulnerable version:

# when updating log4j, please update also docs/java-api/index.asciidoc
log4j = 2.11.1
slf4j = 1.6.2

Vulnerability:
apache/logging-log4j2#608

Please look at it and advice on the best course of action to secure an elastic cluster and prevent compromise ASAP.

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    >bugneeds:triageRequires assignment of a team area label

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions