← All Kestrel Security B.V. advisories

Log4j updated to 2.24.3 in Kestrel SIEM 7.2.419

CriticalPublished 2 Sept 2026

CVE: CVE-2021-44228, CVE-2021-45046

Affected products: Kestrel SIEM Platform

Affected versions: 7.2.400 – 7.2.418

Fixed versions: 7.2.419 and later

Summary: A stale build-cache record shipped log4j-core 2.14.1 metadata in the 7.2 appliance SBOM. The shipped image runs 2.24.3; build 7.2.419 removes the stale record and this advisory documents the verification.

Kestrel SIEM 7.2 appliance images between builds 7.2.400 and 7.2.418 carried a stale SBOM record for log4j-core 2.14.1.

The running correlation engine links log4j-core 2.24.3; the 2.14.1 entry was a build-cache artefact. Build 7.2.419 regenerates the SBOM from the shipped image and adds a manifest diff to CI.

No exploitation path existed in shipped builds. Customers pinning versions should move to 7.2.419 so their SBOM evidence matches the image.

Machine-readable advisory

This advisory is also available as a CSAF 2.0 document (category csaf_security_advisory) for automated consumption.

CSAF 2.0 document (JSON)

Security advisory published by Kestrel Security B.V. under Regulation (EU) 2024/2847, Annex I Part II(4).