# Log4J CVE Mitigation for Neo4j

**URL:** <https://community.neo4j.com/t/log4j-cve-mitigation-for-neo4j/48856>\
**Category:** Announcements\
**Tags:** security, sandbox, aura, cve\
**Created:** [December 11, 2021, 2:05pm UTC](https://community.neo4j.com/t/log4j-cve-mitigation-for-neo4j/48856 "2021-12-11T14:05:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![michael.hunger](https://sea1.discourse-cdn.com/flex021/user_avatar/community.neo4j.com/michael.hunger/32/27377_2.png) [@michael.hunger](https://community.neo4j.com/u/michael.hunger)\
**Post date:** [December 11, 2021, 2:05pm UTC](https://community.neo4j.com/t/log4j-cve-mitigation-for-neo4j/48856/1 "2021-12-11T14:05:57Z")

</div>

Hi Everyone,

We are writing to alert you of a potential vulnerability issue - CVE-2021-44228

> **[Log4Shell: RCE 0-day exploit found in log4j, a popular Java logging package |...](https://www.lunasec.io/docs/blog/log4j-zero-day/)**
>
> Given how ubiquitous log4j is, the impact of this vulnerability is quite severe. Learn how to fix Log4Shell, why it's bad, and what a working exploit requires in this post.

The issue impacts **Neo4j version 4.2+**.

Versions 4.0 and 4.1 use slf4j-log4j12 and are not impacted.

Version 4.2 introduces using log4j2

> <https://github.com/neo4j/neo4j/blob/4.2/pom.xml#L140>

We are working on a fix in 4.2 and up (Neo4j versions 4.3 and 4.4),

Meanwhile **please use the configuration setting** in your `$PATH_TO_NEO4J/conf/neo4j.conf` or `/etc/neo4j/neo4j.conf`. (That is also the case for Neo4j Desktop)

```auto
dbms.jvm.additional=-Dlog4j2.formatMsgNoLookups=true

dbms.jvm.additional=-Dlog4j2.disable.jmx=true

```

which mitigates the problem.

A **restart will be required** for the configuration property change to be read and applied.

In Neo4j Sandbox the issue has already been addressed for new sandboxes.

In Neo4j AuraDB the issue has also been mitigated.

The docker images have also been updated with a config setting disabling jmx.

Cheers, Michael

---

<div class="post-metadata">

**Author:** ![michael.hunger](https://sea1.discourse-cdn.com/flex021/user_avatar/community.neo4j.com/michael.hunger/32/27377_2.png) [@michael.hunger](https://community.neo4j.com/u/michael.hunger)\
**Post date:** [December 14, 2021, 11:21pm UTC](https://community.neo4j.com/t/log4j-cve-mitigation-for-neo4j/48856/2 "2021-12-14T23:21:17Z")

</div>

## Update:

We now have an official page with ongoing updates here

> **[Information Security Management at Neo4j](https://neo4j.com/security/)**
>
> Information Security Management at Neo4j Neo4j hosts a dedicated security team that, under the leadership of the Neo4j CISO, manages information security. A risk-based approach ensures that focus is where it’s needed the most at all times. Found an...

New releases are out, which upgraded the log4j dependency to a non-vulnerable version (2.15.0)  
also on [DockerHub](https://hub.docker.com/_/neo4j?tab=tags&page=1&name=4.)

- 4.4.1
- 4.3.8
- 4.2.12

**Please upgrade to these new releases**

If you **can not** upgrade use the mentioned mitigation.

For a more drastic mitigation you can also remove the `JndiLookup` class from the neo4j-logging.jar  
Might need to install `zip` first on your systems.

```auto
zip -q -d /usr/share/neo4j/lib/neo4j-logging-4*.jar org/neo4j/logging/shaded/log4j/core/lookup/JndiLookup.class

```

---

<div class="post-metadata">

**Author:** ![michael.hunger](https://sea1.discourse-cdn.com/flex021/user_avatar/community.neo4j.com/michael.hunger/32/27377_2.png) [@michael.hunger](https://community.neo4j.com/u/michael.hunger)\
**Post date:** [December 18, 2021, 1:18pm UTC](https://community.neo4j.com/t/log4j-cve-mitigation-for-neo4j/48856/3 "2021-12-18T13:18:51Z")

</div>

The new security page for the log4j issue (gets ongoing updates): [Apache Log4j Security Vulnerability](https://neo4j.com/security/log4j/)

Recent patch releases with log4j 2.16.0 -\> 4.4.2, 4.3.9, 4.2.13 also for the public Docker image.
