Hi, We were asked to remove log4j-core.jar and other log4jXXX.jar related files from Confluence ,JIRA & GIT servers. Kindly confirm if there is any impact to the application if they ask us to r...
Dear, The version we use for Confluence is 7.13.2, which is scanned for vulnerabilities. Apache Log4j2 Remote code execution vulnerability (CVE-2021-44228) &nbs...
Is my Confluence Wiki 7.13.3 version impact with Log4j vulanarability(CVE-2021-44228)?
Dear Atlassian Support-Team, currently there is a critical vulnerability Critical vulnerability in log4j published (CVE-2021-44228) in Java issued by BSI with alert level red. Could you please so b...
Hi Atlassian Support team, We followed the steps to check our Jira & Confluence Server to identify the Log4J vulnerability. However, we just found the files with WEB-INF/lib/log4j2-stacktrace-or...
Hello I checked Log4j's vulnerability in Jira. So I delivered the information to the company's security team, and the company's policy was instructed to upgrade Log4j to version 2.17.0 So I'm going...
Installed Version 7.17.4 Per https://confluence.atlassian.com/security/multiple-products-security-advisory-log4j-vulnerable-to-remote-code-execution-cve-2021-44228-1103069934.html the mitigatio...
is confluence atlassian version 5.1.3 using BAD version of Log4j, if yes please share the plan to upgrade to 2.16 or 2.17. on server we could find below jars in our installation path. ./confluence-...
Have updated to the latest Bitbucket 7.19.1 on my Windows server as per Atlassian guidance: https://confluence.atlassian.com/security/multiple-products-security-advisory-log4j-vulnerable-to-remote-c...
I see stash-java-client-core latest version uses log4j 1.X. I am aware log4j 1.X is not vulnerable to the Zero Day vulnerability but still I prefer to upgrade to 2.17 Has anyone found ho...
Hi, could anyone help to find out if the following plugins are affected by the log4j vulnerability? Or do I have to write to the manufacturers individually? Adaptavist ScriptRunner for J...
Since Atlassian's Response to Log4j (CVE-2021-44228), two more vulnerabilities have been unearthed and Log4j2 has been updated to v2.17.0 to patch the vulns. Do CVE-2021-45046 or CVE-2021-...
Hi all, We are using Atlassian Jira Project Management Software v8.0.2, I would like to know whether there's any threat of the Apache Log4j vulnerability? Regards, Lukasz
Hi all, I'm using JIRA software v8.8.0, I would like to know whether there's any threat of the Apache Log4j vulnerability on JIRA Software v8.8.0? My JIRA web address is in the form "http://10.xxx...
To whom it may concern hello, My name is Kosuge from Yahoo Japan Corporation. I have a question about the Apache Log4j vulnerability*. Can you tell us about the impact of the vulnerability on...
I use Jira v8.9.0 , want to know what to do with log4j vulnerability
I can see the instructions for the on-prem version of the atlassian products on the log4net vunerabilities but on Cloud is not specifically mentioned. So, are we going to have a vunera...
Is anyone else using Tenable to scan their servers for security vulnerabilities like CVE-2021-44228? It appears that Tenable does not recognize the remediation for Bitbucket / Elasticsearch. ...
There is a known remote code execution vulnerability (CVE-2021-44228) in Apache Log4j which is an open-source logging utility which causes major security threat. Does Cloudbees DevOptics plugin...
After the discovery of the vulnerability of version 1.2.17 of Log4j when is Atlassian intending to add the latest version of Log4j as part of the standard on premise installation?
Hello. Do CVE-2021-44228 and CVE-2021-45046 vulnerabilities affect Jira Service Management versions 4.13? Thank you in advance.
/app/atlassian/bitbucket/7.4.2/app/WEB-INF/lib/log4j-api-2.11.1.jar /app/atlassian/bitbucket/7.4.2/app/WEB-INF/lib/log4j-to-slf4j-2.12.1.jar /app/atlassian/bitbucket/7.4.2/elasticsearch/lib/log4j-a...
Hello Atlassian team, I would like to know what are the stepts to follow to apply this manual remediation: "The simplest remediation is to set the JVM option -Dlog4j2.formatMs...
Regarding your FAQ: https://confluence.atlassian.com/kb/faq-for-cve-2021-44228-1103069406.html when you say: The javax.jms API is included in the application's CLASSPATH Whic...
We are using the Bamboo server on a closed network. Recently, I received a call saying that a vulnerability was also found in the 1.2.xx version of log4j. As a result of checking the Atlassian home...
Copied to clipboard