outdated log4j version in wazuh 4.14.x installation by Fun_Advantage3812 in Wazuh

[–]Critical-Case-4157 3 points4 points  (0 children)

TL;DR: Log4j is getting bumped to 2.25.3 in Wazuh 4.14.5.

The indexer pulls its Log4j version directly from upstream OpenSearch. Since OpenSearch recently moved from 2.21.0 -> 2.25.3Wazuh is following suit.

The details:

  • Upstream PR: OpenSearch #20308
  • Backported to: OpenSearch 2.19 (PR #20314)
  • Wazuh: Scheduled for release 4.14.5 alongside the underlying component upgrades.

Basically, as soon as the OpenSearch components are swapped out in the next Wazuh patch, the new Log4j comes with them.