# Graylog and the CVE-2021-45046 vulnerability

**URL:** <https://community.graylog.org/t/graylog-and-the-cve-2021-45046-vulnerability/22064>\
**Category:** Graylog Central (peer support)\
**Created:** [December 15, 2021, 8:43am UTC](https://community.graylog.org/t/graylog-and-the-cve-2021-45046-vulnerability/22064 "2021-12-15T08:43:16Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![michielp](https://avatars.discourse-cdn.com/v4/letter/m/b487fb/32.png) [@michielp](https://community.graylog.org/u/michielp)\
**Post date:** [December 15, 2021, 8:43am UTC](https://community.graylog.org/t/graylog-and-the-cve-2021-45046-vulnerability/22064/1 "2021-12-15T08:43:16Z")

</div>

As [Log4Shell Update: Second log4j Vulnerability Published (CVE-2021-44228 + CVE-2021-45046) | LunaSec](https://www.lunasec.io/docs/blog/log4j-zero-day-update-on-cve-2021-45046/) says setting noMsgFormatLookups to True will not work any more. The current Graylog update only includes setting the noMsgFormatLookups variable.

When can we expect that this issue get solved?

---

<div class="post-metadata">

**Author:** ![NominaSumpta](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/nominasumpta/32/6212_2.png) [@NominaSumpta](https://community.graylog.org/u/NominaSumpta)\
**Post date:** [December 15, 2021, 2:06pm UTC](https://community.graylog.org/t/graylog-and-the-cve-2021-45046-vulnerability/22064/2 "2021-12-15T14:06:11Z")

</div>

See [Fixes for log4j CVE-2021-44228 by mpfz0r · Pull Request #11786 · Graylog2/graylog2-server · GitHub](https://github.com/Graylog2/graylog2-server/pull/11786#issuecomment-994715935)

---

<div class="post-metadata">

**Author:** ![mpfz0r](https://avatars.discourse-cdn.com/v4/letter/m/eb9ed0/32.png) [@mpfz0r](https://community.graylog.org/u/mpfz0r)\
**Post date:** [December 15, 2021, 5:15pm UTC](https://community.graylog.org/t/graylog-and-the-cve-2021-45046-vulnerability/22064/3 "2021-12-15T17:15:50Z")

</div>

> [@michielp](#):
>
> The current Graylog update only includes setting the noMsgFormatLookups variable.

That’s not correct. We also updated log4j to 2.15.0. We just added the noMsgFormatLookups setting as a second measure.

---

<div class="post-metadata">

**Author:** ![shake76](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shake76/32/8758_2.png) [@shake76](https://community.graylog.org/u/shake76)\
**Post date:** [December 15, 2021, 5:49pm UTC](https://community.graylog.org/t/graylog-and-the-cve-2021-45046-vulnerability/22064/4 "2021-12-15T17:49:05Z")

</div>

Im currently upgrade Graylog to version 3.3.15, just wondering if that include the fix for the last issue mentioned here or a new image is going to be created, I will appreciate your comments on this

---

<div class="post-metadata">

**Author:** ![Arie](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/arie/32/8094_2.png) [@Arie](https://community.graylog.org/u/Arie)\
**Post date:** [December 15, 2021, 7:32pm UTC](https://community.graylog.org/t/graylog-and-the-cve-2021-45046-vulnerability/22064/5 "2021-12-15T19:32:07Z")

</div>

It could not to be enouch, but case dependent, log4j 2.16.0 is already released.

---

<div class="post-metadata">

**Author:** ![alessio.dapelo](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@alessio.dapelo](https://community.graylog.org/u/alessio.dapelo)\
**Post date:** [December 16, 2021, 11:24am UTC](https://community.graylog.org/t/graylog-and-the-cve-2021-45046-vulnerability/22064/6 "2021-12-16T11:24:38Z")

</div>

> [@mpfz0r](#):
>
> updated log4j to 2.15.0

How to update log4j from 2.11.1 to 2.16.0 ?  
i use graylog 4.2.3 and elasticsearch 7.10.2 build oss

---

<div class="post-metadata">

**Author:** ![Arie](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/arie/32/8094_2.png) [@Arie](https://community.graylog.org/u/Arie)\
**Post date:** [December 17, 2021, 5:35pm UTC](https://community.graylog.org/t/graylog-and-the-cve-2021-45046-vulnerability/22064/7 "2021-12-17T17:35:22Z")

</div>

Update graylog 2 the latest version you even get log4j 2.16 with it 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [December 31, 2021, 5:35pm UTC](https://community.graylog.org/t/graylog-and-the-cve-2021-45046-vulnerability/22064/8 "2021-12-31T17:35:40Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
