log4j vulnerability

63 views
Skip to first unread message

siim....@gmail.com

unread,
Dec 13, 2021, 5:59:42 AM12/13/21
to MailArchiva
Looks like latest  MailArchiva 8.4.1 is affected by the recent log4j vulnerability. 
https://nvd.nist.gov/vuln/detail/CVE-2021-44228

Can we expect an update or a patch any time soon? Till then is there a workaround? 

jamie

unread,
Dec 13, 2021, 9:08:48 AM12/13/21
to MailArchiva

The library may be present due to a dependency of a dependency, but the library is not in use. MailArchiva uses logback, not log4j. 
I hope this clarifies!

siim....@gmail.com

unread,
Dec 13, 2021, 9:58:45 AM12/13/21
to MailArchiva
Cool. thank you for clearing this ;) 

G. S. Nord

unread,
Dec 15, 2021, 2:44:35 AM12/15/21
to MailArchiva
I am using Mailarchiva 8 on Windows. I found the following files in C:\ProgramData\MailArchiva\Tomcat\webapps\ROOT\WEB-INF\lib

log4j-api-2.12.1.jar (276.771 Bytes) 10.3.2021
log4j-core-2.12.1.jar (1.674.433 Bytes) 10.3.2021
log4j-over-slf4j-1.7.32.jar (23.767 Bytes) 9.9.2021

I renamed them to *.ja_ and started Mailarchiva service. It seems running like normal, nothing special in the log files.


Jamie

unread,
Dec 15, 2021, 2:54:50 AM12/15/21
to MailArchiva
I dont think its necessary because MailArchiva uses LOGBACK, however we will in any case, upgrade log4j lib to the patched version in the next release.

Jamie

unread,
Dec 16, 2021, 12:26:02 PM12/16/21
to MailArchiva
As stated prior, we don't believe MailArchiva is vulnerable since we are using logback as our logging framework, although the log4j library is included with the build as a dependency of a dependency. As far as we can tell the lib is not used.  If you are worried about it download 8.4.2 from https://mailarchiva.com/downloads/ and upgrade. This version has log4j libraries excluded from the build altogether.
Reply all
Reply to author
Forward
0 new messages