Hi, We're using BitBucket Server 7.17.10 which comes with bundled elastic search for our internal projects. A recent security scan has shown that our BB contains vulnerable version of log4j 2...
Are the vulnerabilities in Apache Log4j ie: CVE-2019-17571,CVE-2020-9488,CVE-2022-23302,CVE-2022-23305,CVE-2022-23307,CVE-2023-2646 are applicable to JIRA Software 9.1.1?
We need to get rid of log4j version 1.2.16 from our Jira 7.7.1 Jira Server. We don't have time right now to consider upgrading our Jira version. It's recommended that we move to log4j version 2.17.1....
...zure-monitor/agents/data-sources-custom-logs) i.e. log rotation not supported which is the default of Confluence and Jira. ( Servers are also on Azure Vm.s) log4j in Jira and Confluence out of the box d...
Hello, we have Bitbucket server 5.16.1 bundled with elastisearch. The Log4j-core version shows 2.8.2 , this need to be upgraded to the latest version. Can you please let us know how we can p...
...ork of Log4j 1.2.17, which while not vulnerable to CVE-2021-44228, is vulnerable to a new but similar vulnerability that can be exploited when a trusted party is present and the JMS A...
About Apache Log4j Security Vulnerabilities,The official recommendation is to upgrade 7.17.4. And We can see the Release notes:BSERV-13087 - Remove unused log4j-core and update log4j-api to 2.16.0...
Hi Team, As per recent scan we found out that there are lot of places where Atlassian bundled plugins are using log4j 1.2.17 inside. We are using Jira Service Management 8.13. Any suggestions h...
Hi Atlassian Support team, We followed the steps to check our Jira & Confluence Server to identify the Log4J vulnerability. However, we just found the files with WEB-INF/lib/log4j2-stacktrace-o...
I see stash-java-client-core latest version uses log4j 1.X. I am aware log4j 1.X is not vulnerable to the Zero Day vulnerability but still I prefer to upgrade to 2.17 Has anyone found h...
Hi, could anyone help to find out if the following plugins are affected by the log4j vulnerability? Or do I have to write to the manufacturers individually? Adaptavist ScriptRunner for J...
Hi all, We are using Atlassian Jira Project Management Software v8.0.2, I would like to know whether there's any threat of the Apache Log4j vulnerability? Regards, Lukasz
To whom it may concern hello, My name is Kosuge from Yahoo Japan Corporation. I have a question about the Apache Log4j vulnerability*. Can you tell us about the impact of the vulnerability o...
Regarding your FAQ: https://confluence.atlassian.com/kb/faq-for-cve-2021-44228-1103069406.html when you say: The javax.jms API is included in the application's CLASSPATH Whic...
pls share the impact of Log4J vulenrability on below Jira plugins Stellarity Software PowerShell Task for Bamboo (Server) beecom AG JIRA Suite Utilities codescape Scrum Poker for J...
Hi pls provide the impact of log4j issue on below bamboo plugins Stellarity Software PowerShell Task for Bamboo (Server) AutoTestingTools UFT for Bamboo for Bamboo (Server) Mibex S...
Hi Should we be replacing the log4j library on our servers or waiting for an Atlassian release. Does this even affect Jira and Confluence? https://nakedsecurity.sophos.com/2021/12/10/l...
What command(s) can you execute on the the server that will locate the version of log4j your instance of Jira is running?
Hi, Has anyone encountered with problems regarding log outputs in Scriptrunner on the latest long-term support release of Jira Server? No matter if in consoles or post functions, no logs...
Jira 7.13から8.13にアップグレードしたところ、Index関連の機能改善のためか、atlassian-jira.logに記録される情報が増えています。その中でも、 com.atlassian.jira.index.ha com.atlassian.versioning.EntityVersioninManagerWithStats から多数出力されています。これらの記録のため...
I have a Jira plug-in running on the production server and it writes the its logs to data/atlassian/jira/logs/catalina.out, but I want this plug-in to write logs to a different file from now on,...
...refer the comfort of log4j.
which package names logging levels should be changed in the log4j.properties file in order to see the logs for issue created/failed
I'm a Confluence server plug-in developer and am trying to the log4j system supposedly built into Confluence server to output some diagnostics to the atlassian-confluence.log file. I've g...
When logging uses access to Confluence if the user hits a page such as the below: https://xxxxxxx.com/pages/viewpage.action?pageId=15212342342 The Log4J does not record the full url it eleminates t...
Copied to clipboard
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.