Hi all,
we just released Search Guard V52.5.0 compatible with Elasticsearch 7.16.1:
Elasticsearch 7.16.1 contains fixes for the Log4Shell security vulnerability, and we advise all users to upgrade to this version as soon as possible. See also the corresponding post from Elastic:
For older versions of Elasticsearch 7.x we recommend adding following JVM option manually:
Dlog4j2.formatMsgNoLookups=true
In a standard Elasticsearch installation, this option can be added to
<ES config directory>/jvm.options
We will also release Search Guard for Elasticsearch 6.8.21 shorty.
Thanks!
Jochen and the Searh Guard Team
Search Guard (®) is an Elasticsearch plugin that offers encryption, authentication, and authorization.
Coded with love in Berlin, Denmark, Sweden, Italy, Ukraine, and the US.
Search Guard is a trademark of floragunn GmbH, registered in the U.S. and in other countries.
Elasticsearch, Kibana, Logstash, and Beats are trademarks of Elasticsearch BV, registered in the U.S. and in other countries.