Since Atlassian's Response to Log4j (CVE-2021-44228), two more vulnerabilities have been unearthed and Log4j2 has been updated to v2.17.0 to patch the vulns.
Do CVE-2021-45046 or CVE-2021-45105 have any impact on the Atlassian fork of Log4j2?
Please also review https://jira.atlassian.com/browse/JRASERVER-62838 where you can see the progress of a version 2 implementation for Log4j within Atlassian products.
As of today, version 2 is not available but a special patched version of Log4j is used with Jira, for example.
CVE-2021-45046 has been covered here FAQ for CVE-2021-44228 and CVE-2021-45046 . But yes waiting for the update on the other one definitely.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.