Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Apache Log4j2 vulnerability

Audra Bonacki
Contributor
December 14, 2021

Has anyone been able to get a response from Atlassian or seen any press release or info about what Atlassian is doing about Apache Log4j2 vulnerability? I opened a ticket yesterday and because of the level of severity was shown we would be contacted within 2 hours. It's been a day.

2 answers

0 votes
Rodney Nissen - ReleaseTEAM
Community Champion
December 15, 2021

From what I can read, the version of log4j that Atlassian uses for on-prem systems is not vulnerable out of the box.  If you are running on-prem, you can configure it to be vulnerable, but you have to perform multiple steps to do so. 

They have already mitigated the vulnerability in cloud, so it is no longer a concern.

You can read up on it here: https://thejiraguy.com/2021/12/15/log4shell/

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
VERSION
8.7.1
TAGS
AUG Leaders

Atlassian Community Events