bitvoodoo Advisories
Space shortcuts
Space Tools
bitvoodoo Advisories BVADVIS

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 34 Next »

Contents

Date

 

Product
  • Apache Log4j 2
Vulnerability

Critical

CVECVE-2021-44228, CVE-2021-45046
Official linkMultiple Products Security Advisory - Log4j Vulnerable To Remote Code Execution - CVE-2021-44228
Log4Shell Information - bitvoodoo apps

Looking for information about bitvoodoo apps? Look here.


Dear customer,

On Thursday 9th December, developers and security researchers found a security vulnerability in Apache Log4j 2.

Update : Atlassian put out a Security Advisory for this exploit under Multiple Products Security Advisory - Log4j Vulnerable To Remote Code Execution - CVE-2021-44228.

Update : Atlassian updated the Security Advisory to inform about a finding that shows that some Bitbucket Versions are affected. We created a info page on Bitbucket under Bitbucket Security Advisory - 2021-12-16.

Update : Atlassian updated their FAQ with information regarding CVE 2021-45046, see FAQ for CVE-2021-44228 and CVE-2021-45046.
 

What you need to know

A security vulnerability was discovered in Apache Log4j 2. Log4j is a popular logging package for Java.

This is a security issue affecting a broad range of software based upon Java. Atlassian products such as Jira and Confluence run on Java and also utilize Log4j.

Atlassian products

Bitbucket Server & Data Center

All other Server & Data Center Products

Most Atlassian on-premise applications use an outdated version of Log4j and are not affected if you didn't modify Log4j yourself. See FAQ for CVE-2021-44228 and CVE-2021-45046.

Cloud Products

Atlassian secured their cloud products and has not identified compromised systems. The on-demad applications and are not affected.

What should I do?

This refers to all products except for Bitbucket, if you use Bitbucket Server or Data Center, please refer to Bitbucket Security Advisory - 2021-12-16!

You host your application yourself 

If you have never customized the settings of Log4j inside the Atlassian installation, you are on the safe side. As your Atlassian application uses the default configuration of Log4j, you are not affected by the exploit.

If you have set Log4j to work with JMS Appenders or are unsure, follow the instructions "How can I mitigate this exploit?" in the FAQ for CVE-2021-44228 and CVE-2021-45046.

Third-party apps can still pose a risk. Atlassian is reviewing all apps and informs the vendors it the find a security risk. We cannot determine whether there is a risk in this respect in your installation. As we cannot speak for other app vendors, we cannot be sure that other apps are safe. You might need to get in touch with other Atlassian Marketplace vendors.

We have checked our bitvoodoo apps and found them to be risk-free. You can find more information about our apps here: Log4Shell - bitvoodoo apps - 2021-12-13

Please contact our support if you need assistance.

Your application is hosted with bitvoodoo

We have checked our installations according to the information in the FAQ. The installations have no configurations that could lead to misuse. As your Atlassian application uses the default configuration of Log4j, you are not affected by the exploit.

Third-party apps can still pose a risk. Atlassian is reviewing all apps and informs the vendors it the find a security risk. We cannot determine whether there is a risk in this respect in your installation. As we cannot speak for other app vendors, we cannot be sure that other apps are safe. You might need to get in touch with other Atlassian Marketplace vendors.

We have checked our bitvoodoo apps and found them to be risk-free. You can find more information about our apps here: Log4Shell - bitvoodoo apps - 2021-12-13

Please contact our support if you need assistance.

You use Confluence or Jira Cloud

Atlassian secured their cloud products and has not identified compromised systems.

This vulnerability has been mitigated for all Atlassian cloud products previously using vulnerable versions of Log4j. To date, our analysis has not identified compromise of Atlassian systems or customer data prior to the patching of these systems. Atlassian customers are not vulnerable, and no action is required.

No steps needed.

Further Recommendation

Please check all Java based software, beside Atlassian products, running in your organisation as this is a serious security risk.

Further Reading

Support

If you still have questions or concerns regarding this advisory, please contact the bitvoodoo support via support.bitvoodoo.ch.



  • No labels
bitvoodoo Advisories BVADVIS