Skip to content

Conversation

@jackshirazi
Copy link
Contributor

What does this PR do?

While the agent is not directly exploitable, and any indirect exploit would require permissions that would in any case expose the application completely (so this minor attach vector would never be applied), nevertheless we will exclude log4j SocketAppender to eliminate any possibility of exploitation of https://nvd.nist.gov/vuln/detail/CVE-2025-68161

@jackshirazi jackshirazi requested a review from a team as a code owner January 5, 2026 13:47
@github-actions
Copy link

github-actions bot commented Jan 5, 2026

🤖 GitHub comments

Just comment with:

  • run docs-build : Re-trigger the docs validation. (use unformatted text in the comment!)

@jackshirazi jackshirazi merged commit a90942f into elastic:main Jan 7, 2026
26 of 28 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants