Package
elasticsearch-9.5-iamguarded
Component
log4j-api
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable log4j-api classes are embedded inside a prebuilt upstream APM agent uber-jar that is consumed as a published binary artifact rather than compiled from source, so no build-time dependency pin alters its contents. The agent shades log4j-api 2.25.4 transitively through the ECS logging layout library, whose latest release still pins that version. The most recent agent release carries the same embedded version, so no available upstream artifact resolves this finding. A fix requires the ECS logging layout to adopt log4j-api 2.25.5 or later and a subsequent agent release to pick it up.
Status