Afaik ES 7.16.2 is using log4j 2.17
https://www.elastic.co/guide/en/elasticsearch/reference/current/release-notes-7.16.2.html
Hi Kristian,
Atlassian notes here that they won't be able to update the bundled elasticsearch to a higher version due to licensing changes. The latest version of bitbucket includes mitigation for the log4j issue found inside elasticsearch. It's also included in the LTS version 7.17.4.
Here's the official ticket: https://jira.atlassian.com/browse/BSERV-13088
If you need to update elasticsearch you can always run elasticsearch on a separate server and connect it to bitbucket. Atlassian's got a great guide on how to do this here:
Hope this helps.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.