Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Current »

Release Date

CVE ID

CVE-2021-44228

We do not include our own log4j in our apps. The logging is done by the logging functionality provided by Atlassian.

This means: our apps would only be affected by the log4j vulnarability if Jira was. This - according to Atlassian - is not the case. You can find more information about this in this FAQ: https://confluence.atlassian.com/security/multiple-products-security-advisory-log4j-vulnerable-to-remote-code-execution-cve-2021-44228-1103069934.html

We have not implemented the configuration described there: Developer Documentation - Using your own log4j configuration for your plugin . We think apps that have followed this documentation may cause problems.

  • No labels