Vulnerability in Apache Log4j (CVE-2021-44228)
Background
Impact on anDREa and all its services
Production
anDREa does not use Log4J or forks in production.
Impact: NONE
Actions: no action needed
update: 2021/12/13
Workspaces that might have installed Log4J2 on their VM(s), Windows or Linux, are not vulnerable for no Workspace is allowed to have inbound access.
Related Articles
myDRE is NOT vulnerable for Text4Shell (CVE-2022-42889)
TL;DR myDRE is NOT vulnerable for Text4Shell (CVE-2022-42889). The National Cyber Security Center (NCSC) has announced that a vulnerability with impact High/High (CVE-2022-42889) has been identified in Apache Commons Text v1.5-v1.9. It is being ...
myDRE is NOT vulnerable for CVE-2022-26809 - Serious Vulnerabilities in Microsoft Windows Workplaces and Servers
Situation Last “patch Tuesday” Microsoft disclosed and fixed a large number of serious vulnerabilities in Microsoft Windows. One of these vulnerabilities is identified as CVE-2022-26809 with a CVSS score of 9.8 (scale 1-10). CVE-2022-26809 is a ...
Low severity vulnerability in Linux VMs patch
TL;DR: We have found a low severity vulnerability in Linux VMs. It has been patched for newly created VMs. Existing VMs can be self-service patched by downloading and running the script below. What happened? While troubleshooting a Linux VM, we ...
Awareness - Convenience & Security
Introduction - the case of copy-paste: local <-> VM On myDRE you cannot copy-paste text from or into a VM. As a Jupyter Lab user myself (Python) that heavily makes use on Google to find solutions, I do miss this copy-paste option. It would be so much ...
Enhancing VM Performance & Security: Important Update Coming Soon
We're enhancing VM performance and security with the Azure Monitoring Agent (AMA), starting April 26th, 2024. This tool streamlines management and facilitates towards ISO27001/NIS2 compliance. Contact Research Support by April 26th, 17:00 if any VMs ...