lagoon-images 21.12.1
Security Release
This release actions the most recent guidance on the log4j vulnerabilities at https://logging.apache.org/log4j/2.x/security.html
To comply with the advised mitigation, all instances of the log4j-core.jar files have been examined, and the JndiLookup.class
removed
This applies the following images:
- uselagoon/logstash-6
- uselagoon/logstash-7
- uselagoon/elasticsearch-6
- uselagoon/elasticsearch-7
- uselagoon/solr7.7
- uselagoon/solr7.7-drupal
- uselagoon/solr7
- uselagoon/solr7-drupal
- uselagoon/solr8
- uselagoon/solr8-drupal
We will continue to monitor CVE-2021-45046 and CVE-2021-44228
Changes in this release
- remove the JndiLookup class from the classpaths for CVE-2021-45046 and CVE-2021-44228 @tobybellwood (#365)