Uploaded image for project: 'Chat Solution'
  1. Chat Solution
  2. CSN-5774

Merge CSN-5761 - Resolve CVE-2021-44228 Log4J vulnerability

    XMLWordPrintable

Details

    • Software (SOFTWARE)
    • Sprint# 62 (Dec 6 - 17)

    Description

      Issue

      CVE-2021-44228 is identified in Hybrid Chat components and other Java-based components. The vulnerability is identified in the following components

      1. CCM
      2. Communication Server
      3. Routing Engine
      Business Impact

      Customer Channel Manager in Hybrid Chat is vulnerable due to CVE-2021-44228. The Customer Channel Manager (CCM) is responsible for handling communication with all channels except WebChat. This vulnerability may impact all customer channels except WebChat. 

       

      Implementation

      This vulnerability is caused by Log4J2 in versions older than 2.15.0. It is recommended to update the Log4J2 library to at least ≥ 2.16.0 which resolves the following two vulnerabilities:

      1. CVE-2021-44228 - Critical
      2. CVE-2021-45056 - Low

       

      Attachments

        Activity

          People

            awais.aslam Awais Aslam
            awais.aslam Awais Aslam
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: