1377 - Log4Shell vulnerability

Modified on Tue, 5 Aug at 1:20 PM

Background

A critical vulnerability known as "Log4Shell" has been found in the Log4j Java library. Details can be found here. A subsequent vulnerability has also been discovered, as documented here.

 

Mitigation

The Log4Shell and related vulnerabilities apply only to Log4j v2 and above, and affected only an internal component of Redstor's backend Data Management Platform that is not publicly exposed to the Internet. This has already been mitigated by upgrading to Log4j v2.17.0.

Log4j is also used on the SE and ESE agents, but these utilise versions that are not affected by Log4Shell. Details can be found in Article 1376.

Note: Other Redstor software, including the AccountServer and StorageServer, is not written in Java so does not use Log4j, and therefore does not require mitigation.

 

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article