Log4Shell - log4j.appender

Andreas Beyeler
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 23, 2021

Hello 

One of our customers is using atlassian confluence server. I have read the article https://confluence.atlassian.com/kb/faq-for-cve-2021-44228-1103069406.html

In "C:\Program Files\Atlassian\Confluence\confluence\WEB-INF\classes\log4j.properties" I cannot find a line with "org.apache.log4j.net.JMSAppender".

But there are plenty of lines beginning with log4j.appender. Is this configuration affected from the vulnerability as well?

Just want to be sure. Thank you very much for your help!

Greetings

Andreas

1 answer

0 votes
Andreas Beyeler
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
January 18, 2022

Any advices?

Suggest an answer

Log in or Sign up to answer