Vulnerability in Apache Log4j (CVE-2021-44228)
Vulnerability in Apache Log4j (CVE-2021-44228)
Background
See:
https://nvd.nist.gov/vuln/detail/CVE-2021-44228
Impact on anDREa and all its services
Production
anDREa does not use Log4J or forks in production.
Impact: NONE
Actions: no action needed
update: 2021/12/13
Workspaces that might have installed Log4J2 on their VM(s), Windows or Linux, are not vulnerable for no Workspace is allowed to have inbound access.