On December 9, Atlassian became aware of the vulnerability CVE-2021-44228 - Log4j.
This vulnerability has been mitigated for all Atlassian cloud products previously using vulnerable versions of Log4j. To date, our analysis has not identified compromise of Atlassian systems or customer data prior to the patching of these systems. Atlassian customers are not vulnerable, and no action is required.
No Atlassian on-premises products are vulnerable to CVE-2021-44228.
Some on-premises products use an Atlassian-maintained fork of Log4j 1.2.17, which is not vulnerable to CVE-2021-44228. We have done additional analysis on this fork and confirmed a new but similar vulnerability that can only be exploited by a trusted party. For that reason, Atlassian rates the severity level for on-premises products as low.
For further detailed information, please visit;
https://confluence.atlassian.com/kb/faq-for-cve-2021-44228-1103069406.html
Jodie Vlassis
Senior Trust & Security SME
Atlassian
Sydney, Australia
11 accepted answers
20 comments