Security

When is Log4j 2.17 availability for Splunk Enterprise 8.1?

FrancoiseMathy
New Member

Hello, 

As found on "Splunk Security Advisory for Apache Log4j", I could read that "Unless CVE-2021-45105 or CVE-2021-44832 increase in severity, Splunk will address these vulnerabilities as part of the next regular maintenance release of each affected product. Customers also have the option to remove Log4j Version 2 from Splunk Enterprise out of an abundance of caution. "

CVE-2021-44832 concerns a vulnerability found in version 2.17.
Thus as far as I understand, the vulnerability of Log4j 2.17 will be solved in next maintenance release.

I am running Splunk Enterprise 8.1.7.2 and the version of Log4j in it is 2.16.  This version of Log4j has been deleted.  But my management is asking when the version 2.17 will be available. I believe in next maintenance release.

Thus can you please tell me when the next maintenance release will be released for Splunk Enterprise 8.1? Thanks

Labels (1)
Tags (2)
0 Karma

FrancoiseMathy
New Member

Thanks for your answer Stefanie.
But there is no plan to include version 2.17 of Log4j in version 8.1?

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

Stefanie
Builder

Splunk Version 8.2.5 has been released for some time now. It addresses the log4j issue.

What's New in 8.2.5
Splunk Enterprise 8.2.5 was released on February 16, 2022. This release includes version 2.17.1 of Apache Log4j. It also resolves the issues described in Fixed issues.

https://docs.splunk.com/Documentation/Splunk/8.2.5/ReleaseNotes/MeetSplunk 

Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...

New Splunk Innovations Enhance Performance and Accelerate Troubleshooting

Splunk is excited to announce new releases that empower ITOps and engineering teams to stay ahead in ever ...