NCSC-NL / log4shell

Operational information regarding the log4shell vulnerabilities in the Log4j logging library.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Elasticsearch wrong version

realjax opened this issue · comments

commented

The listing for elasticsearch mentions a version < 6.8.9. but this seems very odd because that is over a year old, it should probably read version 6.8.22 ( see screenprint)

Screenshot 2021-12-20 at 09 37 56
9

Please see the attached link that is the correct version numbers that is used on Elastic's page on the vulnerability, https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476

commented

@maertsen this is still incorrect. Now it only lists he correct version for release 7 and no longer for 6.