diff --git a/ansible/roles/elasticsearch/defaults/main.yml b/ansible/roles/elasticsearch/defaults/main.yml index 10232d6997..1d4ecd892f 100644 --- a/ansible/roles/elasticsearch/defaults/main.yml +++ b/ansible/roles/elasticsearch/defaults/main.yml @@ -38,7 +38,7 @@ elasticsearch_enable_keystone_registration: False elasticsearch_cluster_name: "kolla_logging" es_heap_size: "1g" -es_java_opts: "{% if es_heap_size %}-Xms{{ es_heap_size }} -Xmx{{ es_heap_size }}{%endif%}" +es_java_opts: "{% if es_heap_size %}-Xms{{ es_heap_size }} -Xmx{{ es_heap_size }}{%endif%} -Dlog4j2.formatMsgNoLookups=true" ####################### # Elasticsearch Curator diff --git a/releasenotes/notes/security-log4j-1be047799f8e590a.yaml b/releasenotes/notes/security-log4j-1be047799f8e590a.yaml new file mode 100644 index 0000000000..ae4a3c3e77 --- /dev/null +++ b/releasenotes/notes/security-log4j-1be047799f8e590a.yaml @@ -0,0 +1,5 @@ +--- +security: + - | + Adds mitigation for the Apache Log4j2 Remote Code Execution (RCE) + Vulnerability in Elasticsearch - CVE-2021-44228.