log4j shell - CVE-2021-44228

Confluence User - 13 Dec, 2021

Hi !
Is joget using some version on log4 that are vulnerabilty to log4j shell - CVE-2021-44228 ?
(from my little investigation I think it used older version < 2 that seems not to be impacted but it would be great to confirm).
Thanks !

security

3


13 Dec, 2021
confluenceUser
1
confluenceUser

Hi, regarding the recently disclosed critical vulnerability in Apache Log4j CVE-2021-44228 ( https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-44228 ), kindly note that this vulnerability only affects Apache Log4j versions from 2.0-beta9 to 2.14.1 ( https://logging.apache.org/log4j/2.x/security.html ). All Joget versions do not use these Log4J versions and are not affected by this vulnerability.

15 Dec, 2021
confluenceUser
confluenceUser

Hi Andrew

Thanks for your answer.

I get that Joget does not use any of the Apache Log4j versions from 2.0-beta9 to 2.14.1, can you confirm then which version Joget is using of log4j?

15 Dec, 2021
confluenceUser
confluenceUser

You can view all the current libraries and their version in the Joget folder at "[JogetRoot]\apache-tomcat-8.5.72\webapps\jw\WEB-INF\lib\".

RELATED QUESTIONS

Your answer


To answer a question you'll need an account.

Print