# Keep in mind that Pydio 8 with elasticsearch can use a vulnerable log4j version

**URL:** <https://forum.pydio.com/t/keep-in-mind-that-pydio-8-with-elasticsearch-can-use-a-vulnerable-log4j-version/4217>\
**Category:** Pydio 8\
**Tags:** linux\
**Created:** [December 17, 2021, 1:43am UTC](https://forum.pydio.com/t/keep-in-mind-that-pydio-8-with-elasticsearch-can-use-a-vulnerable-log4j-version/4217 "2021-12-17T01:43:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vincent\_de\_Belgique](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/vincent_de_belgique/32/1624_2.png) [@Vincent\_de\_Belgique](https://forum.pydio.com/u/Vincent_de_Belgique)\
**Post date:** [December 17, 2021, 1:43am UTC](https://forum.pydio.com/t/keep-in-mind-that-pydio-8-with-elasticsearch-can-use-a-vulnerable-log4j-version/4217/1 "2021-12-17T01:43:35Z")

</div>

Hello, I found log4j on my (good old) Pydio 8 on Linux Debian Linux, in elastic search, (the Pydio elastic search plugin is installed).

You can read here [Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31 - Security Announcements - Discuss the Elastic Stack](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476) the full explanation of elastic search vulnerabilities

and a more practical résumé here : [Mitigate Log4j / Log4Shell in Elasticsearch (CVE-2021-44228)](https://xeraa.net/blog/2021_mitigate-log4j2-log4shell-elasticsearch/)

What we did ? For certain elastic search version, an easy fix was to remove the vulnerable library inline in the jar file, that’s what we did :

cd /usr/share/elasticsearch/lib/

# create a backup of the jar

cp log4j-core-2.7.jar log4j-core-2.7.jar.VULNERABLE

# verfify the vulnerabble is in the librairy

jar tvf lib/log4j-core-_.jar | grep -i JndiLookup  
response : org/apache/logging/log4j/core/lookup/JndiLookup.class  
 #remove the class  
zip -d log4j-core-2.7.jar org/apache/logging/log4j/core/lookup/JndiLookup.class  
 #verify the class is no more present  
jar tvf log4j-core-_.jar | grep -i JndiLookup  
#restart elastic search  
service elasticsearch restart  
service elasticsearch status

🕶

Hope this can help !

---

<div class="post-metadata">

**Author:** ![bsinou](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/bsinou/32/476_2.png) [@bsinou](https://forum.pydio.com/u/bsinou)\
**Post date:** [December 22, 2021, 10:42am UTC](https://forum.pydio.com/t/keep-in-mind-that-pydio-8-with-elasticsearch-can-use-a-vulnerable-log4j-version/4217/2 "2021-12-22T10:42:07Z")

</div>

Thanks for reporting!

Anyway, this can be seen as one more reminder that it is a good time to switch to Cells !! 😄

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex032/uploads/pydio/original/2X/6/61f19fa52ec15fd4250db51aea351adba0e831fd.png) [@system](https://forum.pydio.com/u/system)\
**Post date:** [January 21, 2022, 10:42am UTC](https://forum.pydio.com/t/keep-in-mind-that-pydio-8-with-elasticsearch-can-use-a-vulnerable-log4j-version/4217/3 "2022-01-21T10:42:16Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
