We are using the Bamboo server on a closed network.
Recently, I received a call saying that a vulnerability was also found in the 1.2.xx version of log4j.
As a result of checking the Atlassian homepage, it was confirmed that the 1.2.17 version of log4j exists on both the Bamboo server and the Bamboo target server.
I want to know if that jar file is used and if it is vulnerable to security.
Additionally, it would be appreciated if you could tell us the exact config name of log4j used in Bamboo.
I don't see the log4j config file on the target server side.[bamboo-agent]
If there is no config file for log4j , I wonder if it doesn't matter.
thank you.