The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Regarding Log4J 1.X files which have reached End of Life

mayank ashok
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
January 27, 2022

We are using Jira v7.13.13, and we see number of folders using the log4j-1.X jar files which have already reached end of life since year 2016.

Below are few of the folders with these jar files:

/opt/atlassian/jira/lib/log4j-1.2.16.jar

/opt/devops/atlassian-jira-software-7.13.11-standalone/lib/log4j-1.2.16.jar

/var/atlassian/application-data/jira/plugins/.osgi-plugins/felix/felix-cache/bundle73/version0.0/jira-projects-plugin-4.5.35.jar-embedded/META-INF/lib/log4j-1.2.16.jar

For now, we have mitigated by removing the JMSAppender.class from these jar files. But since this is using EOL product, we are advised to migrate it to log4j-2.X versions. Please advise and provide us the steps for these.

 

Thanks

Daljinder Singh

Mobile number: +65-87271801

1 answer

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

Post a new question

1 vote
Benjamin
Community Champion
January 27, 2022

Hi @mayank ashok ,

 

I'm not sure if upgrading is warranted. If you like to follow the status of upgrading the version, please follow this ticket.

https://jira.atlassian.com/browse/JRASERVER-62838

IF the concern is vulnerability, then you just need to be on Atlassian maintain fork version. Please see link for details:

https://confluence.atlassian.com/security/multiple-products-security-advisory-log4j-vulnerable-to-remote-code-execution-cve-2021-44228-1103069934.html

 

Thanks,

 

Ben