← All Kestrel Security B.V. advisories
Log4j updated to 2.24.3 in Kestrel SIEM 7.2.419
CriticalPublished 2 Sept 2026
CVE: CVE-2021-44228, CVE-2021-45046
Affected products: Kestrel SIEM Platform
Affected versions: 7.2.400 – 7.2.418
Fixed versions: 7.2.419 and later
Summary: A stale build-cache record shipped log4j-core 2.14.1 metadata in the 7.2 appliance SBOM. The shipped image runs 2.24.3; build 7.2.419 removes the stale record and this advisory documents the verification.
Kestrel SIEM 7.2 appliance images between builds 7.2.400 and 7.2.418 carried a stale SBOM record for log4j-core 2.14.1.
The running correlation engine links log4j-core 2.24.3; the 2.14.1 entry was a build-cache artefact. Build 7.2.419 regenerates the SBOM from the shipped image and adds a manifest diff to CI.
No exploitation path existed in shipped builds. Customers pinning versions should move to 7.2.419 so their SBOM evidence matches the image.
Machine-readable advisory
This advisory is also available as a CSAF 2.0 document (category csaf_security_advisory) for automated consumption.
Security advisory published by Kestrel Security B.V. under Regulation (EU) 2024/2847, Annex I Part II(4).