Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cve-2021-45046 - Upgrade to log4j 2.16 #81867

Closed
2knarf opened this issue Dec 17, 2021 · 3 comments
Closed

cve-2021-45046 - Upgrade to log4j 2.16 #81867

2knarf opened this issue Dec 17, 2021 · 3 comments
Labels
:Core/Infra/Logging Log management and logging utilities dependencies Team:Core/Infra Meta label for core/infra team

Comments

@2knarf
Copy link

2knarf commented Dec 17, 2021

Seems like log4j 2.16 now needs to be used.

https://www.lunasec.io/docs/blog/log4j-zero-day-severity-of-cve-2021-45046-increased/

@2knarf 2knarf added >bug needs:triage Requires assignment of a team area label labels Dec 17, 2021
@DJRickyB DJRickyB added :Core/Infra/Logging Log management and logging utilities dependencies and removed >bug needs:triage Requires assignment of a team area label labels Dec 17, 2021
@elasticmachine elasticmachine added the Team:Core/Infra Meta label for core/infra team label Dec 17, 2021
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-core-infra (Team:Core/Infra)

@grcevski
Copy link
Contributor

Thanks @2knarf, please see the following PR and discussion #81759.

@costin
Copy link
Member

costin commented Dec 19, 2021

Superseded through #81902 - Upgrade to Log4J 2.17.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
:Core/Infra/Logging Log management and logging utilities dependencies Team:Core/Infra Meta label for core/infra team
Projects
None yet
Development

No branches or pull requests

5 participants