Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,298,443
Community Members
 
Community Events
165
Community Groups

Upgrading Apache log4j software in Bamboo

Atlassian Bamboo version 5.15.5 build 51518 - 28 Mar 17

log4j1.x is EOL and has many vulnerabilities. We are upgrading the log4j-1.2.17.jar software with the latest version log4j 2.17.2.  The bamboo service is not running at all.

We have the below queries.

1. Is there any configuration that Bamboo will run only on log4j1.x.

2. How to upgrade the latest log4j2.x ?

3. Do we need to upgrade the Bamboo version itself?

1 answer

0 votes

Hello @ganeshmurthi_s,

Bamboo does not support Log4j 2.x. Atlassian has a forked version of Log4J that has fixes for all the recent vulnerabilities.

Please upgrade to the latest versions of Bamboo 8.0, 8.1 or 8.2 to be covered.

More information: https://confluence.atlassian.com/kb/faq-for-cve-2021-44228-1103069406.html

 

Regards,

Eduardo Alvarenga

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Bamboo

Bamboo Data Center on Kubernetes

Hi, If you are running self-managed environments and looking to adopt modern infrastructure, Bamboo Data Center can now be deployed in a Kubernetes cluster. By leveraging Kubernetes, you can easily...

961 views 3 8
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you