Package
sonarqube
Component
log4j-core
Latest update
Fixed version
26.7.0.124771-r0
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
26.7.0.124771-r0Status
Status
Impact
This vulnerability exists in log4j-core which is bundled/shaded inside two upstream-controlled artifacts in the Elasticsearch tarball: (1) log4j-core 2.19.0 inside elasticsearch-log4j-*.jar (Elasticsearch's repackaging of log4j with JndiLookup.class stripped per Log4Shell mitigation, see https://github.com/elastic/elasticsearch/blob/v8.19.14/libs/log4j/build.gradle); (2) log4j-core 2.25.0 shaded inside elastic-apm-agent-java8-1.55.0.jar. As pre-built binary artifacts, the embedded dependencies cannot be updated independently. This requires a new upstream release of Elasticsearch with updated bundled dependencies. Latest Elasticsearch v8.19.14 and v9.3.3 still pin log4j=2.19.0 in build-tools-internal/version.properties; the apm-agent 1.55.x line (latest v1.55.6) ships log4j-core 2.25.0 shaded. Fix version: 2.25.4.
Status