<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>Apache Log4j2 vulnerability for Liferay 7.2.1 CE and Elastic search</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121307936" />
  <subtitle>Apache Log4j2 vulnerability for Liferay 7.2.1 CE and Elastic search</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121307936</id>
  <updated>2026-04-03T19:40:05Z</updated>
  <dc:date>2026-04-03T19:40:05Z</dc:date>
  <entry>
    <title>Apache Log4j2 vulnerability for Liferay 7.2.1 CE and Elastic search</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121307935" />
    <author>
      <name>Karthik Nainupatruni</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121307935</id>
    <updated>2021-12-24T08:47:19Z</updated>
    <published>2021-12-24T08:47:19Z</published>
    <summary type="html">&lt;p&gt;Hi All,&lt;br /&gt; We have been using the Liferay CE 7.2.1 GA2 and Elastic
  search 6.4.3 in our project.&lt;/p&gt;
&lt;p&gt;With persisting  latest effect of log4J Shell Vulnerability issue ,
  we have  been added &lt;strong&gt;-Dlog4j2.formatMsgNoLookups=true in
  &lt;/strong&gt;JVM options however Apache log4j project saying is not 100%
  safe by adding this configuration.&lt;/p&gt;
&lt;p&gt;Here are my 2 questions to the Liferay community ,Kindly answer or
  throw some insight on this.&lt;/p&gt;
&lt;p&gt;1) How to mitigate Log4j Shell vulnerability issue for LR and Elatci search?&lt;/p&gt;
&lt;p&gt;2) how to apply &lt;strong&gt;log4J  2.17.0 &lt;/strong&gt;version in Liferay and
  elastic search?&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;
  &lt;a href="https://liferay.dev/blogs/-/blogs/log4j2-vulnerability-fixing-the-jar?_com_liferay_blogs_web_portlet_BlogsPortlet_showFlags=true&amp;amp;scroll=_com_liferay_blogs_web_portlet_BlogsPortlet_discussionContainer"&gt;https://liferay.dev/blogs/-/blogs/log4j2-vulnerability-fixing-the-jar?_com_liferay_blogs_web_portlet_BlogsPortlet_showFlags=true&amp;amp;scroll=_com_liferay_blogs_web_portlet_BlogsPortlet_discussionContainer&lt;/a&gt;&lt;/p&gt;</summary>
    <dc:creator>Karthik Nainupatruni</dc:creator>
    <dc:date>2021-12-24T08:47:19Z</dc:date>
  </entry>
</feed>
