# Stardog 7.8.1 available

**URL:** https://community.stardog.com/t/stardog-7-8-1-available/3411
**Category:** Announcements
**Created:** [December 10, 2021, 10:18pm UTC](https://community.stardog.com/t/stardog-7-8-1-available/3411 "2021-12-10T22:18:47Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![evren](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.stardog.com/evren/32/1515_2.png) [@evren](https://community.stardog.com/u/evren)
#### Post date: [December 10, 2021, 10:18pm UTC](https://community.stardog.com/t/stardog-7-8-1-available/3411/1 "2021-12-10T22:18:48Z")

</div>

On December 9, 2021 a serious security vulnerability ([CVE-2021-44228](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228)) was disclosed in the widely used logging library [Log4j](https://logging.apache.org/log4j). This vulnerability affects wide range of software including the Stardog platform. This vulnerability allows an attacker to execute code on a remote server.

On December 10, 2021, a new version of Log4j was released to address the vulnerability and the Stardog engineering team immediately started working on a new release. The release 7.8.1 is now generally available. The only change in 7.8.1 is addressing this vulnerability.

We strongly urge you to take **one** of the following two actions:

1. **Upgrade to Stardog 7.8.1 (Recommended)**

2. If you are using Stardog 7.4.2 or above, and cannot upgrade, then set the following JVM property `-Dlog4j2.formatMsgNoLookups=true` based on your deployment method:

Additional mitigation strategies are outlined in the ([CVE-2021-44228](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228)) report.
