Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Log4j2 vulnerabilities - the saga continues

SS
Contributor
December 20, 2021

Since Atlassian's Response to Log4j (CVE-2021-44228), two more vulnerabilities have been unearthed and Log4j2 has been updated to v2.17.0 to patch the vulns.

Do CVE-2021-45046 or CVE-2021-45105 have any impact on the Atlassian fork of Log4j2?

 

2 answers

Suggest an answer

Log in or Sign up to answer
0 votes
Daniel Ebers
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 31, 2022

Please also review https://jira.atlassian.com/browse/JRASERVER-62838 where you can see the progress of a version 2 implementation for Log4j within Atlassian products.
As of today, version 2 is not available but a special patched version of Log4j is used with Jira, for example.

0 votes
Venkateshwar Aynala December 20, 2021

CVE-2021-45046 has been covered here FAQ for CVE-2021-44228 and CVE-2021-45046 . But yes waiting for the update on the other one definitely.

TAGS
AUG Leaders

Atlassian Community Events