# Logs4j CVE-2021-44228 Vulnerability

**URL:** <https://discuss.prometheus.io/t/logs4j-cve-2021-44228-vulnerability/647>\
**Category:** General Help/Support\
**Created:** [December 13, 2021, 8:30am UTC](https://discuss.prometheus.io/t/logs4j-cve-2021-44228-vulnerability/647 "2021-12-13T08:30:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kavirajan](https://avatars.discourse-cdn.com/v4/letter/k/a183cd/32.png) [@Kavirajan](https://discuss.prometheus.io/u/Kavirajan)\
**Post date:** [December 13, 2021, 8:30am UTC](https://discuss.prometheus.io/t/logs4j-cve-2021-44228-vulnerability/647/1 "2021-12-13T08:30:23Z")

</div>

We are using Prometheus. Hope you are aware about the critical vulnerability reported on log4j CVE-2021-44228. We would like to understand if there is any impact. If there is any impact please suggest when the fix is going to be available and if any workaround is available.

---

<div class="post-metadata">

**Author:** ![stuart](https://dub1.discourse-cdn.com/flex017/user_avatar/discuss.prometheus.io/stuart/32/18_2.png) [@stuart](https://discuss.prometheus.io/u/stuart)\
**Post date:** [December 13, 2021, 9:04am UTC](https://discuss.prometheus.io/t/logs4j-cve-2021-44228-vulnerability/647/2 "2021-12-13T09:04:30Z")

</div>

Prometheus itself is written in Go rather than Java, so has no issue. However there are various bits of the echosystem (e.g. third party exporters) that might be using Java and therefore could have issues. So it really depends on what you are using. I’d suggest taking stock of what is being used, and then for all the pieces that are written in Java check for updated versions (if needed) from their creators.

---

<div class="post-metadata">

**Author:** ![Kavirajan](https://avatars.discourse-cdn.com/v4/letter/k/a183cd/32.png) [@Kavirajan](https://discuss.prometheus.io/u/Kavirajan)\
**Post date:** [December 14, 2021, 9:23am UTC](https://discuss.prometheus.io/t/logs4j-cve-2021-44228-vulnerability/647/3 "2021-12-14T09:23:09Z")

</div>

Thanks Stuart for the information, is there any official details article i can through ? or can i expect anything soon ?

---

<div class="post-metadata">

**Author:** ![stuart](https://dub1.discourse-cdn.com/flex017/user_avatar/discuss.prometheus.io/stuart/32/18_2.png) [@stuart](https://discuss.prometheus.io/u/stuart)\
**Post date:** [December 14, 2021, 10:55am UTC](https://discuss.prometheus.io/t/logs4j-cve-2021-44228-vulnerability/647/4 "2021-12-14T10:55:22Z")

</div>

As it only affects Java applications and Prometheus isn’t a Java application there isn’t really anything “official” to say.

With regards to other applications which are Java and are part of the broader Prometheus ecosystem you’d need to look to whoever owns/manages them for something “official” as it isn’t something the core Prometheus developers can help with (as they aren’t involved with other parts of the ecosystem)

---

<div class="post-metadata">

**Author:** ![Kavirajan](https://avatars.discourse-cdn.com/v4/letter/k/a183cd/32.png) [@Kavirajan](https://discuss.prometheus.io/u/Kavirajan)\
**Post date:** [December 15, 2021, 2:37pm UTC](https://discuss.prometheus.io/t/logs4j-cve-2021-44228-vulnerability/647/5 "2021-12-15T14:37:48Z")

</div>

Thanks Stuart,

Thank You for the confirmation.  
In addition to CVE-2021-44228, there two more vulnerabilities were reported,

[https://nvd.nist.gov/vuln/detail/CVE-2021-4104](https://nvd.nist.gov/vuln/detail/CVE-2021-4104)  
[https://nvd.nist.gov/vuln/detail/CVE-2021-45046](https://nvd.nist.gov/vuln/detail/CVE-2021-45046)

We would like to understand if there is any impact on Prometheus ?  
If there is any impact please suggest when the fix is going to be available and if any workaround is available.

Looking forward.

---

<div class="post-metadata">

**Author:** ![stuart](https://dub1.discourse-cdn.com/flex017/user_avatar/discuss.prometheus.io/stuart/32/18_2.png) [@stuart](https://discuss.prometheus.io/u/stuart)\
**Post date:** [December 15, 2021, 3:38pm UTC](https://discuss.prometheus.io/t/logs4j-cve-2021-44228-vulnerability/647/6 "2021-12-15T15:38:17Z")

</div>

As before these are both referring to issues with Java applications, so not applicable to the core Prometheus system which are written in Go.
