Alibaba Cloud discovered a remote code execution (RCE) vulnerability in Apache Log4j 2 and reported it to Apache. This topic covers the impact and remediation steps.
Impact
The impact on Elasticsearch is described in Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31 and Elasticsearch 5.0.0-5.6.10 and 6.0.0-6.3.2: Log4j CVE-2021-44228, CVE-2021-45046 remediation.
Affected Alibaba Cloud Elasticsearch and Logstash versions:
-
Elasticsearch: V5.5.3, V5.6.16, V6.3.2, and V6.7.0 (with the kernel version of V1.3.0)
To check the kernel version, open the Basic Information page (View the basic information of an instance). Click Update and Upgrade and select Kernel Patch Update to display the kernel version.
-
Logstash: V6.7 and V7.4
Solutions
Configuration recommendations
Security recommendations:
-
Do not enable Public Network Access unless necessary. If enabled, allow only required IP addresses in the whitelist (Manage IP address whitelists).
-
Do not install unofficial plug-ins on your Elasticsearch cluster.
Elasticsearch service remediation
Alibaba Cloud released patches on December 28, 2021 for Elasticsearch V5.5.3 and V5.6.16, Logstash V6.7 and V7.4, and on January 19, 2022 for Elasticsearch V6.3.2 and V6.7.0 (kernel V1.3.0). Restart your affected cluster to apply the fix (Procedure).
Notes:
-
This fix applies only to Elasticsearch V5.5.3, V5.6.16, V6.3.2, V6.7.0 (kernel V1.3.0), Logstash V6.7, and V7.4.
-
Restarting or performing a blue-green update does not affect online business, but schedule it during off-peak hours.
Recommended update schedule
Starting December 28, 2021, you can update clusters in the listed regions. Update within the recommended time ranges for stability.
|
Recommended update time |
Region name |
Region ID |
|
From December 28, 2021 |
China (Shanghai) |
cn-shanghai |
|
Singapore |
ap-southeast-1 |
|
|
Australia (Sydney) Closed Down |
ap-southeast-2 |
|
|
Malaysia (Kuala Lumpur) |
ap-southeast-3 |
|
|
Indonesia (Jakarta) |
ap-southeast-5 |
|
|
Japan (Tokyo) |
ap-northeast-1 |
|
|
From December 29, 2021 |
China (Hangzhou) |
cn-hangzhou |
|
China (Qingdao) |
cn-qingdao |
|
|
China (Zhangjiakou) |
cn-zhangjiakou |
|
|
India (Mumbai) Closed Down |
ap-south-1 |
|
|
China East 1 Finance |
cn-hangzhou-finance |
|
|
China East 2 Finance |
cn-shanghai-finance-1 |
|
|
China North 2 Ali Gov 1 |
cn-north-2-gov-1 |
|
|
From December 30, 2021 |
Germany (Frankfurt) |
eu-central-1 |
|
US (Virginia) |
us-east-1 |
|
|
US (Silicon Valley) |
us-west-1 |
|
|
China (Shenzhen) |
cn-shenzhen |
|
|
China (Beijing) |
cn-beijing |
|
|
China (Hong Kong) |
cn-hongkong |
|
|
UK (London) |
eu-west-1 |
Procedure
-
Elasticsearch cluster
Restart the instance in the console. On the Basic Information page of your instance, click Restart in the upper-right corner. Select Node Role, choose the nodes to restart (all nodes except Kibana and Nginx nodes), and select the Blue-green Update checkbox. The vulnerability is fixed after restart. Restart a cluster or node.
-
Logstash cluster
Restart the instance in the console. On the Basic Information page of the instance, click Restart in the upper-right corner and select Cluster. The vulnerability is fixed after restart. Restart an instance or node.
WarningLogstash clusters do not require a blue-green update. Performing one changes the cluster nodes and may cause pipeline data loss.