# SolidFire and CVE-2021-44228 Apache Log4j Vulnerability

Where can I get the Log4j patch for SolidFire

If you haven't enabled VVOLs on SolidFire (Element, eSDS), i.e. VASA service hasn't been enabled, there's no need to do anything.

But if you want to patch anyway, you can find the links [here](https://mysupport.netapp.com/site/article?lang=en&page=%2FAdvice_and_Troubleshooting%2FData_Storage_Software%2FElement_Software%2FElement_Software_-_Apache_Log4j_Vulnerability_-_Workaround&type=solution).

- SUST-1210 - for SolidFire v12 to 12.3.1
- SUST-1211 - for SolidFire v11.3 to 11.8

If you upgrade SolidFire to 12.3.1 or earlier, you need to reapply the patch, so you may as well upgrade to latest SolidFire version you can, and then apply the patch.
