Dear customer, on Thursday 9th december developers and security researcher found a security vulnerability in Apache Log4j 2. What you need to knowA security vulnerability was discovered in Apache Log4j 2. Log4j is a popular logging package for Java.This is a security issue affecting a broad range of software based upon Java. Atlassian products such as Jira and Confluence run on Java and also utilize Log4j. Atlassian productsAtlassian on-premise applications use an outdated version of Log4j and are not affected therefore. As of now Atlassian issued no full Security Adviosory. On 10th of December Atlassian put out a FAQ for this exploit under https://confluence.atlassian.com/kb/faq-for-cve-2021-44228-1103069406.html bitvoodoo appsServer and Data Center
Cloud
What should I do?If you are using the default configuration of Log4j you are not affected, no action is needed. Should you ever have customized the configuration of Log4j to work with JMS Appenders, please disable them by following the mitigation described by Atlassian. As we can't speak for other app vendors, we cannot be certain that other apps are safe. You might need to get in touch with other Atlassian Marketplace vendors. Further Reading |