This release incorporates a fix for the Apache Log4j vulnerability issue disclosed to the public on December 9.
DOWNLOAD LINKS
Tarballs (manual installation):
- Graylog Server
- Graylog Enterprise Server
- Graylog Enterprise Plugin
- Graylog Integrations Plugin
- Graylog Enterprise Integrations Plugin
Please report bugs and any other issues in our GitHub issue tracker. Thank you!
GRAYLOG ENTERPRISE 4.0.14
Released: 2021-12-10
ENTERPRISE
No changes since 4.0.13.
ENTERPRISE INTEGRATIONS PLUGIN
No changes since 4.0.13.
GRAYLOG 4.0.14
Released: 2021-12-10
CORE
Fixed
- Ensure that aggregation events always have a source_streams field for permission checks. Graylog2/graylog2-server#6876 Graylog2/graylog2-server#6877
- Fix permissions for alert events when event definitions don’t select streams. Graylog2/graylog2-server#11301 Graylog2/graylog2-server#11303
- Fix potential issue with duplicate index field type updates. Graylog2/graylog2-server#11504 Graylog2/graylog2-server#11552
- Fix issue where the first day on the traffic graph didn’t show the full day traffic value. Graylog2/graylog2-server#11575
Security
- Fix log4j CVE-2021-44228. Graylog2/graylog2-server#11786
INTEGRATIONS PLUGIN
No changes since 4.0.13.
CHANGELOGS
Let us know what you’d like to have included in our GitHub issue tracker.