log4j java library being exploited CVE-2021-44228

430 views
Skip to first unread message

Dan King

unread,
Dec 11, 2021, 12:32:59 AM12/11/21
to pwm-general
Just wondering if an update is in the works for PWM to address the vulnerabilities in the included log4j libraries? For now I'm just using iptables to drop access from all but a couple whitelisted ip addresses.


Jason Rivard

unread,
Dec 11, 2021, 9:21:08 AM12/11/21
to pwm-general
PWM uses log4j v1 which is not affected by this CVE.

Work is ongoing to migrate to a more modern Java logging API (slf4j+logback) but there is no ETA yet.

Bilal Deniz

unread,
Dec 14, 2021, 1:18:38 AM12/14/21
to pwm-general
Hi Jason,

How about  CVE-2019-17571  (https://www.cvedetails.com/cve/CVE-2019-17571/)

It is mentioned on log4j's page: https://logging.apache.org/log4j/1.2/ and has to do with SocketServer.

I don't know anything about SocketServer. Is PWM using it?

Thanks

Jason Rivard

unread,
Dec 14, 2021, 7:41:34 AM12/14/21
to pwm-general
PWM does not use the SocketServer.  To the best of my knowledge, PWM is not vulnerable to any of the known Log4j v1 CVEs.

Bilal Deniz

unread,
Dec 15, 2021, 5:39:48 PM12/15/21
to pwm-general
Appreciate taking the time to confirm that!
Reply all
Reply to author
Forward
0 new messages