-
Notifications
You must be signed in to change notification settings - Fork 6.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
log4j outdated #642
Comments
@jatty all base images used in this stack are built and released by Elastic, not by us. Sources: https://github.com/elastic/elasticsearch/tree/master/distribution/docker I believe Elastic may re-build recent images, in which case you will get the update automatically after clearing your Docker image cache. |
Related: elastic/elasticsearch#81629 According to the comment, the vulnerability was addressed by disabling the problematic class. Closing as mitigated + out of our control. |
Quick update, I posted a more detailed answer in #645. tl;dr I'm expecting a new patch release of Elastic components to land this week. |
docker containers logstash and elasticsearch use log4j-core-2.14.0.jar and log4j-core-2.11.1.jar
These should be updated to log4j version 2.15 because of CVE-2021-44228
The text was updated successfully, but these errors were encountered: