Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Upgrade Jira's Log4j 1.2.x.jar to Log4j 2.17.0.jar

Jeawoong Choi December 22, 2021

Hello

I checked Log4j's vulnerability in Jira. So I delivered the information to the company's security team, and the company's policy was instructed to upgrade Log4j to version 2.17.0
So I'm going to upgrade it. Is there any problem? Or, please check if there is anything else to guide.

 

Thanks.

1 answer

1 vote
Kurt Klinner
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 22, 2021

@Jeawoong Choi 

 

Jira Server and Data Center use a Atlassian-maintained fork of Log4j 1.2.17, which is not vulnerable to CVE-2021-44228, see also https://confluence.atlassian.com/security/multiple-products-security-advisory-log4j-vulnerable-to-remote-code-execution-cve-2021-44228-1103069934.html

As for CVE-2021-45046 and CVE-2021-45105 Atlassian is going to upgrade to log4j 2.17.0 (or greater) in line with the timeframes detailed in the Atlassian Security Bugfix Policy i think you should wait for the new versions to be provided by Atlassian

 

Cheers

Kurt

Suggest an answer

Log in or Sign up to answer
TAGS
atlassian, atlassian government cloud, fedramp, webinar, register for webinar, atlassian cloud webinar, fedramp moderate offering, work faster with cloud

Unlocking the future with Atlassian Government Cloud ☁️

Atlassian Government Cloud has achieved FedRAMP Authorization at the Moderate level! Join our webinar to learn how you can accelerate mission success and move work forward faster in cloud, all while ensuring your critical data is secure.

Register Now
AUG Leaders

Atlassian Community Events