<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>CVE-2021-44228 mitigation needed?</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121293677" />
  <subtitle>CVE-2021-44228 mitigation needed?</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121293677</id>
  <updated>2026-04-07T12:10:47Z</updated>
  <dc:date>2026-04-07T12:10:47Z</dc:date>
  <entry>
    <title>RE: RE: CVE-2021-44228 mitigation needed?</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121297614" />
    <author>
      <name>Fredi B</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121297614</id>
    <updated>2021-12-14T14:40:34Z</updated>
    <published>2021-12-14T14:40:34Z</published>
    <summary type="html">&lt;p&gt;Cool and relaxed answer.&lt;/p&gt;
&lt;p&gt;However, in your linked blog article there are different answers to
  OPs Question.&lt;/p&gt;
&lt;p&gt;David and Liferay-Support communicate Liferay-Versions below 7.4 do
  not use the affected Version.&lt;/p&gt;
&lt;p&gt;Community and our intern audit reveal that Liferay-Versions below 7.4
  do atleast bring along a affected Version.&lt;/p&gt;
&lt;p&gt;Is it possible to atleast get a concrete statement to the affected version?&lt;/p&gt;
&lt;p&gt;Who can answer the question better than Liferay-Employees or Gurus?&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;</summary>
    <dc:creator>Fredi B</dc:creator>
    <dc:date>2021-12-14T14:40:34Z</dc:date>
  </entry>
  <entry>
    <title>RE: CVE-2021-44228 mitigation needed?</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121296882" />
    <author>
      <name>Olaf Kock</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121296882</id>
    <updated>2021-12-14T09:31:22Z</updated>
    <published>2021-12-14T08:07:13Z</published>
    <summary type="html">&lt;p&gt;As this server had a few issues publishing posts: By now most of the
  excitement might be gone, but for completeness: &lt;a href="https://liferay.dev/blogs/-/blogs/log4j2-zero-day-vulnerability"&gt;https://liferay.dev/blogs/-/blogs/log4j2-zero-day-vulnerability&lt;/a&gt;&lt;/p&gt;</summary>
    <dc:creator>Olaf Kock</dc:creator>
    <dc:date>2021-12-14T08:07:13Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2021-44228 mitigation needed?</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121293676" />
    <author>
      <name>Fernando Fernandez</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121293676</id>
    <updated>2021-12-13T18:02:24Z</updated>
    <published>2021-12-10T17:44:11Z</published>
    <summary type="html">&lt;p&gt;Hi all,&lt;/p&gt;
&lt;p&gt;Just wondering if we should panic about log4j's &lt;a
  href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228"&gt;CVE-2021-44228&lt;/a&gt;.
  Anybody looked into this already?&lt;/p&gt;
&lt;p&gt;TIA&lt;/p&gt;
&lt;p&gt;Fernando&lt;/p&gt;</summary>
    <dc:creator>Fernando Fernandez</dc:creator>
    <dc:date>2021-12-10T17:44:11Z</dc:date>
  </entry>
</feed>
