Security

Voltar para Security Alert

[LES] Elastic's Response to Log4j Exploit (CVE-2021-44228)

Context

Elasticsearch and Liferay Enterprise Search Security Advisory: Dec 11, 2021 (CVE-2021-44228)

Elastic Software Implications

Log4j is used as a component of Elastic products to output log statements that help Elastic and our users to troubleshoot problems.

A security investigation to determine whether there was any impact to Elastic or our customers has been executed and we are centralising the most recent updates from Elastic into the following Security Announcement.

The following products are potentially affected - please see the relevant product specific section of the Security Announcement for more details:

  • APM Java Agent - exposure to the Log4j 2 exploit (CVE-2021-44228) in certain conditions, mitigation requires config setting or upgrade to latest available version (1.28.1)
  • Logstash - Log4j 2 (CVE-2021-44228) exposure to remote code execution on JDKs prior to 8u191. On newer versions of JDKs there is exposure to Denial of Service and information leakage. Requires JndiLookup class removal or update to Logstash version 6.8.21 or 7.16.1 when released on December 13th.
  • Elasticsearch - Log4j 2 (CVE-2021-44228) no exposure to remote code execution for Elasticsearch 6 and 7, but potential exposure to information leakage, full mitigation requires config setting, or update to Elasticsearch version 6.8.21 or 7.16.1 when released on December 13th. Investigation into Elasticsearch 5 is ongoing.

We have validated that the vulnerability does not exist in the following Elastic products:

  • APM Server
  • Beats
  • Cmd
  • Elastic Agent 
  • Elastic Cloud Enterprise (ECE)*
  • Elastic Cloud on Kubernetes (ECK)*
  • Elastic Endgame
  • Elastic Maps Service
  • Endpoint Security
  • Enterprise Search server
  • Fleet Server
  • Kibana
  • Machine Learning
  • Swiftype

*Orchestrated environments should be assessed for impact to deployed products.


 

Elasticsearch is a trademark of Elasticsearch BV, registered in the U.S. and in other countries / Trademarks / Terms / Privacy

Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.

On this page