Skip to content

Commit e3f725f

Browse files
authored
[DOCS] Add CVE-2021-44228 security update to release notes (#81724) (#81733)
Adds a security update for the Apache Log4j 2 CVE-2021-44228 vulnerability to the 7.16.1 and 6.8.21 release notes. # Conflicts: # docs/reference/release-notes/7.16.asciidoc
1 parent cc52210 commit e3f725f

File tree

1 file changed

+15
-0
lines changed

1 file changed

+15
-0
lines changed

docs/reference/release-notes/6.8.asciidoc

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,21 @@
11
[[release-notes-6.8.21]]
22
== {es} version 6.8.21
33

4+
[discrete]
5+
[[security-updates-6.8.21]]
6+
=== Security updates
7+
8+
* A high severity vulnerability
9+
(https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-44228[CVE-2021-44228]) for
10+
https://logging.apache.org/log4j/2.x/[Apache Log4j 2] versions 2.0 to 2.14 was
11+
disclosed publicly on the project's
12+
https://github.com/apache/logging-log4j2/pull/608[GitHub] on December 9, 2021.
13+
+
14+
For information about affected {es} versions and mitigation steps, see our
15+
related
16+
https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476[security
17+
announcement].
18+
419
[[enhancement-6.8.21]]
520
[float]
621
=== Enhancements

0 commit comments

Comments
 (0)