Package
sonarqube
Component
log4j-core
Latest update
Fixed version
26.7.0.124771-r0
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
26.7.0.124771-r0Status
Status
Impact
This vulnerability exists in log4j-core which is bundled/shaded inside two upstream-controlled artifacts in the Elasticsearch tarball: (1) log4j-core 2.19.0 inside elasticsearch-log4j-*.jar (Elasticsearch's repackaging of log4j with JndiLookup.class stripped); (2) log4j-core 2.25.0 shaded inside elastic-apm-agent-java8-1.55.0.jar. As pre-built binary artifacts, the embedded dependencies cannot be updated independently. This requires a new upstream release of Elasticsearch with updated bundled dependencies. Latest Elasticsearch v8.19.14 and v9.3.3 still pin log4j=2.19.0; apm-agent 1.55.x still ships log4j-core 2.25.0. Fix version: 2.25.4.
Status