Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 3 Current »

This page provides information related to the recently published remote code execution (RCE) vulnerability affecting Log4j:

Atlassian host products

Utoolity apps for Atlassian Server products

Not affected beyond the Atlassian host product

All Utoolity Server apps use the SLF4J facade as provided by the respective Atlassian host product via OSGi and do not introduce Log4j on their own. They would thus only be indirectly affected if the Atlassian host product uses a vulnerable version of Log4j – this does not seem to be the case by default, refer to https://confluence.atlassian.com/kb/faq-for-cve-2021-44228-1103069406.html for details.

Utoolity apps for Atlassian Cloud products

Not affected

All Utoolity Cloud apps do not use Log4j and are thus not affected.

  • No labels