Vulnerability in Apache Log4j (CVE-2021-44228)

Vulnerability in Apache Log4j (CVE-2021-44228)

Background


Impact on anDREa and all its services

Production

anDREa does not use Log4J or forks in production.
Impact: NONE
Actions: no action needed

update: 2021/12/13
Workspaces that might have installed Log4J2 on their VM(s), Windows or Linux, are not vulnerable for no Workspace is allowed to have inbound access.

    • Related Articles

    • myDRE is NOT vulnerable for Text4Shell (CVE-2022-42889)

      TL;DR myDRE is NOT vulnerable for Text4Shell (CVE-2022-42889). The National Cyber Security Center (NCSC) has announced that a vulnerability with impact High/High (CVE-2022-42889) has been identified in Apache Commons Text v1.5-v1.9. It is being ...
    • myDRE is NOT vulnerable for CVE-2022-26809 - Serious Vulnerabilities in Microsoft Windows Workplaces and Servers

      Situation Last “patch Tuesday” Microsoft disclosed and fixed a large number of serious vulnerabilities in Microsoft Windows. One of these vulnerabilities is identified as CVE-2022-26809 with a CVSS score of 9.8 (scale 1-10). CVE-2022-26809 is a ...
    • Low severity vulnerability in Linux VMs patch

      TL;DR: We have found a low severity vulnerability in Linux VMs. It has been patched for newly created VMs. Existing VMs can be self-service patched by downloading and running the script below. What happened? While troubleshooting a Linux VM, we ...
    • Awareness - Convenience & Security

      Introduction - the case of copy-paste: local <-> VM On myDRE you cannot copy-paste text from or into a VM. As a Jupyter Lab user myself (Python) that heavily makes use on Google to find solutions, I do miss this copy-paste option. It would be so much ...
    • Enhancing VM Performance & Security: Important Update Coming Soon

      We're enhancing VM performance and security with the Azure Monitoring Agent (AMA), starting April 26th, 2024. This tool streamlines management and facilitates towards ISO27001/NIS2 compliance. Contact Research Support by April 26th, 17:00 if any VMs ...