Security Issue Log4j

svnc December 13, 2021

Dear Team,

due to the current security vulnerability of log4j we need urgent information to how the jira server is affected.

Thanks in advance

 

Regards, Sevinc

2 answers

2 accepted

1 vote
Answer accepted
Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
December 13, 2021

Hi all,

Daniel with Atlassian Support here to let you know our security team has finished its investigation. We have an official response statement here on Community, which you can access at this link.

More information can be found on our advisory page, as well as the previously-published FAQ:

Thanks,
Daniel Eads | Atlassian Support

svnc December 15, 2021

Thank you Daniel

Beeraiah Velumula December 20, 2021

@Daniel Eads - Thank you so much!

jy February 13, 2022

will like to check if there is any intention to upgrade its log4j to 2.17.1?

jy February 13, 2022

https://stackoverflow.com/questions/70334503/cve-2021-44228-and-log4j-1-2-17

As log4j 1.x does not offer a look-up mechanism, it does not suffer from CVE-2021-44228. However, note that log4j 1.x is no longer being maintained.

0 votes
Answer accepted
Mohamed Riza _ServiceRocket_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 13, 2021

Hi @svnc 

You may check the information provided by Atlassian in the following link: https://confluence.atlassian.com/kb/faq-for-cve-2021-44228-1103069406.html. Basically, only if you have org.apache.log4j.net.JMSAppender in your log4j, you may be vulnerable. The mitigation is to disable this temporarily. 

svnc December 15, 2021

Thank you Mohamed!

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
TAGS
AUG Leaders

Atlassian Community Events