Ask Questions and Find Answers
Important:
Ask is now read-only. You can review any existing questions and answers, but not add anything new.
But - don't panic! While ask is no more, we've replaced it with discuss - the new Liferay Discussion Forum! Read more here here or just visit the site here:
discuss.liferay.com
RE: CVE-2021-44228 mitigation needed?
Hi all,
Just wondering if we should panic about log4j's CVE-2021-44228. Anybody looked into this already?
TIA
Fernando
As this server had a few issues publishing posts: By now most of the excitement might be gone, but for completeness: https://liferay.dev/blogs/-/blogs/log4j2-zero-day-vulnerability
Cool and relaxed answer.
However, in your linked blog article there are different answers to OPs Question.
David and Liferay-Support communicate Liferay-Versions below 7.4 do not use the affected Version.
Community and our intern audit reveal that Liferay-Versions below 7.4 do atleast bring along a affected Version.
Is it possible to atleast get a concrete statement to the affected version?
Who can answer the question better than Liferay-Employees or Gurus?
Powered by Liferay™