-
Notifications
You must be signed in to change notification settings - Fork 25.6k
Closed
Labels
Description
Hi Elastic,
A 0-day exploit in log4j package has been published and it looks like ElasticSearch could be affected by a vulnerable version:
elasticsearch/build-tools-internal/version.properties
Lines 16 to 18 in 68836bb
| # when updating log4j, please update also docs/java-api/index.asciidoc | |
| log4j = 2.11.1 | |
| slf4j = 1.6.2 |
Vulnerability:
apache/logging-log4j2#608
Please look at it and advice on the best course of action to secure an elastic cluster and prevent compromise ASAP.
Thanks!
willemdh, ryanotella, rishabhc32, asafhalili, hex1n and 5 moretomcallahan, ravibagri4 and aisbaat0klian