Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

We didn't find string “org.apache.log4j.net.JMSAppender" in our server. Is it unaffected by Log4J?

Srijana Acharya
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 27, 2021

Hi Atlassian Support team,

We followed the steps to check our Jira & Confluence Server to identify the Log4J vulnerability. However, we just found the files with WEB-INF/lib/log4j2-stacktrace-origins-2.2-atlassian-2.jar where the String "org.apache.log4j.net.JMSAppender" was not examined. 

We further followed on the similar Question here: Solved: Is log4j2-stacktrace-origins-2.2-atlassian-2.jar v.. But the exact suggestion is not provided.

Thus, not finding the net.JMSAppender string means that the Server is out of Log4J risks?

Thanks a lot for the Support!

 

 

1 answer

1 accepted

0 votes
Answer accepted
Jack Brickey
Community Champion
December 27, 2021

I would refer you to the following:

Srijana Acharya
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 27, 2021

Hi @Jack Brickey

Thanks for the response. 

We've done the manual testing and didn't find the mentioned string. Now we'll opt for upgrading the Log4J version to 2.17.0. This might ascertain us about the mitigation of vulnerability issue. 

Best Regards,

Srijana

Suggest an answer

Log in or Sign up to answer