Dear Team,
due to the current security vulnerability of log4j we need urgent information to how the jira server is affected.
Thanks in advance
Regards, Sevinc
Hi @svnc
You may check the information provided by Atlassian in the following link: https://confluence.atlassian.com/kb/faq-for-cve-2021-44228-1103069406.html. Basically, only if you have org.apache.log4j.net.JMSAppender in your log4j, you may be vulnerable. The mitigation is to disable this temporarily.
org.apache.log4j.net.JMSAppender in your log4j, you may be vulnerable. The mitigation is to disable this temporarily.
Hi all,
Daniel with Atlassian Support here to let you know our security team has finished its investigation. We have an official response statement here on Community, which you can access at this link.
More information can be found on our advisory page, as well as the previously-published FAQ:
Thanks,Daniel Eads | Atlassian Support
Thank you Daniel
Thank you Mohamed!
@Daniel Eads - Thank you so much!
will like to check if there is any intention to upgrade its log4j to 2.17.1?
It looks like you're new here. Sign in or register to get started.