Advisory: Impact of Log4j 2 CVE-2021-44228 on Snowplow components

Update 2021-12-16:

We are recommending users of Snowplow Mini update to at least 0.13.2 which includes additional mitigations for the log4shell vulnerability.

Out of an abundance of caution, we have also published updates to a variety of Snowplow components. We now recommend running each of these components at the following versions:

Stream Collector: v2.4.3
Enrich: v2.0.4
S3 Loader: v2.1.2
Elasticsearch Loader: v1.0.3 and v2.0.2
GCS Loader: v0.3.2
Snowplow Mini: v0.13.2

1 Like