Vulnerability in Apache Log4j (CVE-2021-44228)

Vulnerability in Apache Log4j (CVE-2021-44228)

Background

See: https://nvd.nist.gov/vuln/detail/CVE-2021-44228

Impact on anDREa and all its services

Production

anDREa does not use Log4J or forks in production.
Impact: NONE
Actions: no action needed

update: 2021/12/13
Workspaces that might have installed Log4J2 on their VM(s), Windows or Linux, are not vulnerable for no Workspace is allowed to have inbound access.