We are looking to see if our servers running Atlassian softwares (JIRA, Confluence, BitBucket) are affected by CVE-2021-44228
(Security issue with log4j)
When we do a search in the server app directories, sone log4j files show up as vulnerable!
As the server softwares vulnerable and if so, are there patches available to remedy these vulnerabilities?
/apps/atlassian/bitbucket/elasticsearch/lib/log4j-core-2.11.1.jar contains Log4J-2.x >= 2.10.0 _VULNERABLE_ :-(