Cloud log4net vunerabilities?

Assassan December 17, 2021

I can see the instructions for the on-prem version of the atlassian products on the log4net vunerabilities but on Cloud is not specifically mentioned. 

 

So, are we going to have a vunerability to in the Jira Cloud version?

If so, what procedures would you recommend. 

1 answer

1 vote
Carlos Garcia Navarro
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
December 17, 2021

Sorry, I just noticed that you write log4net, not log4j (my answer below was for log4j). I did find references for CVE-2018-1285, and CVE-2006-0743. and this other post that referred to CVE-2018-1285:

https://community.atlassian.com/t5/Sourcetree-questions/CVE-2018-1285-apache-log4net-vulnerability/qaq-p/1772292

 

Hi Gary,

This other post may be helpful:

https://community.atlassian.com/t5/Jira-questions/log4j2-vulnerability-CVE-2021-44228/qaq-p/1885742

As described in https://community.atlassian.com/t5/Trust-Security-articles/Atlassian-s-Response-to-Log4j-CVE-2021-44228/ba-p/1886598#M134 :

This vulnerability has been mitigated for all Atlassian cloud products previously using vulnerable versions of Log4j. To date, our analysis has not identified compromise of Atlassian systems or customer data prior to the patching of these systems. Atlassian customers are not vulnerable, and no action is required.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
PERMISSIONS LEVEL
Site Admin
TAGS
AUG Leaders

Atlassian Community Events