All Products
Search
Document Center

Elasticsearch:[Vulnerability notice] Apache Log4j 2 RCE vulnerability

Last Updated:Jun 03, 2026

Alibaba Cloud discovered a remote code execution (RCE) vulnerability in Apache Log4j 2 and reported it to Apache. This topic covers the impact and remediation steps.

Impact

The impact on Elasticsearch is described in Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31 and Elasticsearch 5.0.0-5.6.10 and 6.0.0-6.3.2: Log4j CVE-2021-44228, CVE-2021-45046 remediation.

Affected Alibaba Cloud Elasticsearch and Logstash versions:

  • Elasticsearch: V5.5.3, V5.6.16, V6.3.2, and V6.7.0 (with the kernel version of V1.3.0)

    To check the kernel version, open the Basic Information page (View the basic information of an instance). Click Update and Upgrade and select Kernel Patch Update to display the kernel version.

  • Logstash: V6.7 and V7.4

Solutions

Configuration recommendations

Security recommendations:

  • Do not enable Public Network Access unless necessary. If enabled, allow only required IP addresses in the whitelist (Manage IP address whitelists).

  • Do not install unofficial plug-ins on your Elasticsearch cluster.

Elasticsearch service remediation

Alibaba Cloud released patches on December 28, 2021 for Elasticsearch V5.5.3 and V5.6.16, Logstash V6.7 and V7.4, and on January 19, 2022 for Elasticsearch V6.3.2 and V6.7.0 (kernel V1.3.0). Restart your affected cluster to apply the fix (Procedure).

Notes:

  • This fix applies only to Elasticsearch V5.5.3, V5.6.16, V6.3.2, V6.7.0 (kernel V1.3.0), Logstash V6.7, and V7.4.

  • Restarting or performing a blue-green update does not affect online business, but schedule it during off-peak hours.

Recommended update schedule

Starting December 28, 2021, you can update clusters in the listed regions. Update within the recommended time ranges for stability.

Recommended update time

Region name

Region ID

From December 28, 2021

China (Shanghai)

cn-shanghai

Singapore

ap-southeast-1

Australia (Sydney) Closed Down

ap-southeast-2

Malaysia (Kuala Lumpur)

ap-southeast-3

Indonesia (Jakarta)

ap-southeast-5

Japan (Tokyo)

ap-northeast-1

From December 29, 2021

China (Hangzhou)

cn-hangzhou

China (Qingdao)

cn-qingdao

China (Zhangjiakou)

cn-zhangjiakou

India (Mumbai) Closed Down

ap-south-1

China East 1 Finance

cn-hangzhou-finance

China East 2 Finance

cn-shanghai-finance-1

China North 2 Ali Gov 1

cn-north-2-gov-1

From December 30, 2021

Germany (Frankfurt)

eu-central-1

US (Virginia)

us-east-1

US (Silicon Valley)

us-west-1

China (Shenzhen)

cn-shenzhen

China (Beijing)

cn-beijing

China (Hong Kong)

cn-hongkong

UK (London)

eu-west-1

Procedure

  • Elasticsearch cluster

    Restart the instance in the console. On the Basic Information page of your instance, click Restart in the upper-right corner. Select Node Role, choose the nodes to restart (all nodes except Kibana and Nginx nodes), and select the Blue-green Update checkbox. The vulnerability is fixed after restart. Restart a cluster or node.

  • Logstash cluster

    Restart the instance in the console. On the Basic Information page of the instance, click Restart in the upper-right corner and select Cluster. The vulnerability is fixed after restart. Restart an instance or node.

    Warning

    Logstash clusters do not require a blue-green update. Performing one changes the cluster nodes and may cause pipeline data loss.

FAQ