Welcome Guest! Log in
×

Notice

The forum is in read only mode.
Stambia versions 2.x, 3.x, S17, S18, S19 and S20 are reaching End of Support January, 15th, 2024. Please consider upgrading to the supported Semarchy xDI versions. See Global Policy Support and the Semarchy Documentation.

The Stambia User Community is moving to Semarchy! All the applicable resources have already been moved or are currently being moved to their new location. Read more…

Topic-icon Question Security Notice - Log4j - 2021-12

More
13 Dec 2021 19:00 - 14 Dec 2021 12:08 #1 by Thomas BLETON
Security Notice - Log4j - 2021-12 was created by Thomas BLETON
The Semarchy/Stambia engineering team is monitoring - as part of the build & quality processes - Common Vulnerabilities and Exposures (CVEs) that impact libraries or third-party components shipped in the Semarchy products.

A vulnerability has been reported under the CVE-2021-44228 reference, affecting the Log4J2 (Log4J version 2) library, commonly used in applications for logging services.

To summarize:

- CVE-2021-44228 impacts Log4J2 (Log4J version 2), which is not used in the Stambia core components (Designer, Runtime and Analytics)
The Stambia core components use Log4J1 (Log4J version 1) which is not vulnerable to CVE-2021-44228 attacks as described in the CVE.

- The only component using Log4J2 (Log4J version 2) is the ElasticSearch component. Which is not impacted by the CVE.

A more comprehensive note will be published as soon as possible.
In the meantine, do not hesitate to contact our support team if you have additional questions or need further clarifications.

NB: this forum topic is locked so that it remains a synthetic and clear information source. Please discuss this subject in other topics or contact our support team.
Last edit: 14 Dec 2021 12:08 by Thomas BLETON.
More
15 Dec 2021 10:31 - 15 Dec 2021 10:31 #2 by Thomas BLETON
Replied by Thomas BLETON on topic Security Notice - Log4j - 2021-12
Last edit: 15 Dec 2021 10:31 by Thomas BLETON.