Skip to content

Commit

Permalink
[DOCS] Add CVE-2021-44228 security update to release notes (#81724) (#…
Browse files Browse the repository at this point in the history
…81733)

Adds a security update for the Apache Log4j 2 CVE-2021-44228 vulnerability to
the 7.16.1 and 6.8.21 release notes.
# Conflicts:
#	docs/reference/release-notes/7.16.asciidoc
  • Loading branch information
jrodewig authored Dec 14, 2021
1 parent cc52210 commit e3f725f
Showing 1 changed file with 15 additions and 0 deletions.
15 changes: 15 additions & 0 deletions docs/reference/release-notes/6.8.asciidoc
Original file line number Diff line number Diff line change
@@ -1,6 +1,21 @@
[[release-notes-6.8.21]]
== {es} version 6.8.21

[discrete]
[[security-updates-6.8.21]]
=== Security updates

* A high severity vulnerability
(https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-44228[CVE-2021-44228]) for
https://logging.apache.org/log4j/2.x/[Apache Log4j 2] versions 2.0 to 2.14 was
disclosed publicly on the project's
https://github.com/apache/logging-log4j2/pull/608[GitHub] on December 9, 2021.
+
For information about affected {es} versions and mitigation steps, see our
related
https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476[security
announcement].

[[enhancement-6.8.21]]
[float]
=== Enhancements
Expand Down

0 comments on commit e3f725f

Please sign in to comment.