Skip to content
This repository has been archived by the owner on Jun 16, 2022. It is now read-only.

FEDEX Ship Manager #698

Closed
Gadgetgeek2000 opened this issue Dec 20, 2021 · 5 comments
Closed

FEDEX Ship Manager #698

Gadgetgeek2000 opened this issue Dec 20, 2021 · 5 comments
Labels
PR-requested software Improvements or additions to software list

Comments

@Gadgetgeek2000
Copy link

Gadgetgeek2000 commented Dec 20, 2021

Following files were found on the FEDEX Ship Manager server installation, version 3508:

C:\Program Files (x86)\FedEx\ShipManager\BIN\OfflineFastServicePublisher_lib\log4j-api-2.8.2.jar
C:\Program Files (x86)\FedEx\ShipManager\BIN\OfflineFastServicePublisher_lib\log4j-core-2.8.2.jar
C:\Program Files (x86)\FedEx\ShipManager\BIN\OfflineFastServicePublisher_lib\log4j-jcl-2.8.2.jar
C:\Program Files (x86)\FedEx\ShipManager\BIN\OfflineFastServicePublisher_lib\log4j-slf4j-impl-2.8.2.jar
C:\Program Files (x86)\FedEx\ShipManager\BIN\OfflineFastServicePublisher_lib\log4jna-api-2.0.jar

@Gadgetgeek2000
Copy link
Author

Downloading and installing the latest 3509. Will test again following.
Update

@Gadgetgeek2000
Copy link
Author

Gadgetgeek2000 commented Dec 20, 2021

The Log4J files are updated by the latest installation version 3509.
C:\Program Files (x86)\FedEx\ShipManager\BIN\OfflineFastServicePublisher_lib\log4j-api-2.16.0.jar
C:\Program Files (x86)\FedEx\ShipManager\BIN\OfflineFastServicePublisher_lib\log4j-core-2.16.0.jar
C:\Program Files (x86)\FedEx\ShipManager\BIN\OfflineFastServicePublisher_lib\log4j-jcl-2.16.0.jar
C:\Program Files (x86)\FedEx\ShipManager\BIN\OfflineFastServicePublisher_lib\log4j-slf4j-impl-2.16.0.jar
C:\Program Files (x86)\FedEx\ShipManager\BIN\OfflineFastServicePublisher_lib\log4jna-api-2.0.jar

However, the log4j-core-2.16.0.jar is listed as vulnerable CVE CVE-2021-45105.
JNDILocation: org/apache/logging/log4j/core/lookup/JndiLookup.class

@maertsen
Copy link
Collaborator

hi @Gadgetgeek2000, thanks for your research. Would you mind submitting a PR? Have a look at https://docs.github.com/en/repositories/working-with-files/managing-files/editing-files#editing-files-in-another-users-repository if this is new for you.

@maertsen maertsen added PR-requested software Improvements or additions to software list labels Dec 21, 2021
@Gadgetgeek2000
Copy link
Author

I'm not very familiar with Github but I'll check it out.

@Gadgetgeek2000
Copy link
Author

Just got word from my rep:

The FSM (Fedex Ship Manager) 3510 PLC version tentatively due for release on 1/24 contains the Log4j version 2.17.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
PR-requested software Improvements or additions to software list
Projects
None yet
Development

No branches or pull requests

2 participants