michielp
(michiel)
December 15, 2021, 8:43am
1
As Log4Shell Update: Second log4j Vulnerability Published (CVE-2021-44228 + CVE-2021-45046) | LunaSec says setting noMsgFormatLookups to True will not work any more. The current Graylog update only includes setting the noMsgFormatLookups variable.
When can we expect that this issue get solved?
mpfz0r
(Marco Pfatschbacher)
December 15, 2021, 5:15pm
3
That’s not correct. We also updated log4j to 2.15.0. We just added the noMsgFormatLookups setting as a second measure.
shake76
December 15, 2021, 5:49pm
4
Im currently upgrade Graylog to version 3.3.15, just wondering if that include the fix for the last issue mentioned here or a new image is going to be created, I will appreciate your comments on this
Arie
(Arie van den Heuvel)
December 15, 2021, 7:32pm
5
It could not to be enouch, but case dependent, log4j 2.16.0 is already released.
mpfz0r:
updated log4j to 2.15.0
How to update log4j from 2.11.1 to 2.16.0 ?
i use graylog 4.2.3 and elasticsearch 7.10.2 build oss
Arie
(Arie van den Heuvel)
December 17, 2021, 5:35pm
7
Update graylog 2 the latest version you even get log4j 2.16 with it
system
(system)
Closed
December 31, 2021, 5:35pm
8
This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.