Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[NOT VULNERABLE] - Log4j Remote Code Execution CVE 201-44228 #1381

Closed
MarkAckert opened this issue Dec 13, 2021 · 2 comments
Closed

[NOT VULNERABLE] - Log4j Remote Code Execution CVE 201-44228 #1381

MarkAckert opened this issue Dec 13, 2021 · 2 comments
Labels
Security Items related to security (authentication / authorization)

Comments

@MarkAckert
Copy link
Member

MarkAckert commented Dec 13, 2021

Topline Summary:

Zowe distributions are not affected by this vulnerability.
One unpublished incubator project used the vulnerable library and has been patched.

Details

A recent remote code execution exploit was discovered in the popular Log4j library. See here for more information: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228

The Zowe community reviewed our usage of log4j, and confirmed we do not use the vulnerable libraries in any of our distributions of Zowe.

We did find one instance of the vulnerable library in a Zowe incubator project, the Zowe Java Client SDK, which is now using a newer version of the library. This incubator project is not built or shipped as part of any Zowe distribution. If you are using this incubator project, you are advised to pull/merge the most recent commits.

This issue will be updated if any new information comes in.

@MarkAckert MarkAckert added the Security Items related to security (authentication / authorization) label Dec 13, 2021
@MarkAckert MarkAckert changed the title Log4j Remote Code Execution CVE 201-44228 Vulnerability Record: [NOT VULNERABLE] - Log4j Remote Code Execution CVE 201-44228 Dec 13, 2021
@MarkAckert MarkAckert changed the title Vulnerability Record: [NOT VULNERABLE] - Log4j Remote Code Execution CVE 201-44228 [NOT VULNERABLE] - Log4j Remote Code Execution CVE 201-44228 Dec 13, 2021
@balhar-jakub
Copy link
Member

Closing the issue as the topic and the information was published and at the moment doesn't seem to have any more relevance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Security Items related to security (authentication / authorization)
Projects
None yet
Development

No branches or pull requests

3 participants
@balhar-jakub @MarkAckert and others