Uploaded image for project: 'Chat Solution'
  1. Chat Solution
  2. CSN-5779

Implement a quick fix for Log4J vulnerability in HC

    XMLWordPrintable

Details

    Description

      Vulnerability

      The CVE-2021-442288 vulnerability was found in the following Java-based components in HC:

      1. CCM
      2. Communication Server
      3. Routing Engine

       

      Implementation

      This vulnerability is caused by Log4J2 in versions older than 2.15.0. It is recommended to update the Log4J2 library to at least ≥ 2.16.0 which resolves the following two vulnerabilities:

      1. CVE-2021-44228 - Critical
      2. CVE-2021-45056 - Low

       

      Attachments

        Activity

          People

            awais.aslam Awais Aslam
            jawad.bokhari Jawad Bokhari
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: