Security

When is Log4j 2.17 availability for Splunk Enterprise 8.1?

FrancoiseMathy
New Member

Hello, 

As found on "Splunk Security Advisory for Apache Log4j", I could read that "Unless CVE-2021-45105 or CVE-2021-44832 increase in severity, Splunk will address these vulnerabilities as part of the next regular maintenance release of each affected product. Customers also have the option to remove Log4j Version 2 from Splunk Enterprise out of an abundance of caution. "

CVE-2021-44832 concerns a vulnerability found in version 2.17.
Thus as far as I understand, the vulnerability of Log4j 2.17 will be solved in next maintenance release.

I am running Splunk Enterprise 8.1.7.2 and the version of Log4j in it is 2.16.  This version of Log4j has been deleted.  But my management is asking when the version 2.17 will be available. I believe in next maintenance release.

Thus can you please tell me when the next maintenance release will be released for Splunk Enterprise 8.1? Thanks

Tags (2)
0 Karma

FrancoiseMathy
New Member

Thanks for your answer Stefanie.
But there is no plan to include version 2.17 of Log4j in version 8.1?

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

Stefanie
Builder

Splunk Version 8.2.5 has been released for some time now. It addresses the log4j issue.

What's New in 8.2.5
Splunk Enterprise 8.2.5 was released on February 16, 2022. This release includes version 2.17.1 of Apache Log4j. It also resolves the issues described in Fixed issues.

https://docs.splunk.com/Documentation/Splunk/8.2.5/ReleaseNotes/MeetSplunk 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...