Because of the log4j vulnerability I'm in the need to patch a elasticsearch 5.6.16 instance that I cannot immediately update.
The docker image uses:
- /usr/share/elasticsearch/lib/log4j-core-2.11.1.jar
- /usr/share/elasticsearch/log4j-core-2.11.1.jar
Can elasticsearch 5.6.16 work with log4j-core-2.16?
And is it the correct way to replace both with the core jar that can be found here https://repo1.maven.org/maven2/org/apache/logging/log4j/log4j-core/2.16.0/ ?