cloudfoundry-community / logsearch-boshrelease

A BOSH-scalable ELK release
Apache License 2.0
45 stars 49 forks source link

log4j 2.12.1 in ELK 7.6.1 #188

Open peterellisjones opened 2 years ago

peterellisjones commented 2 years ago

Hi folks, this project uses ELK 7.6.1 which is vulnerable to the recent "log4shell" exploit by virtue of including log4j < 2.15.0. Elastic have stated that the vulnerability can be mitigated by upgrading to ELK 7.8+ (https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476). Are there any plans to update the release?

KshitijaR16 commented 2 years ago

Hi Team, Actually any plan to upgrade this release for log4j2 vulnerability. We are having customer waiting for ELK deployment

julweber commented 2 years ago

+1

SergeyMuha commented 2 years ago

is the any plans to update ELK stack to 7.16.x ? @axelaris