
JavedM (Veracode, Inc.) asked a question.
Veracode Response to Customers Regarding Apache Log4j Vulnerability as of 01/31/2021 1:30 PM
On December 10, 2021, a new critical 0-day vulnerability impacting multiple versions of the popular Apache Log4j logging library was publicly disclosed that, if exploited, could result in Remote Code Execution (RCE) by logging a certain string on affected installations.
This specific vulnerability has been assigned CVE-2021-44228 and is also being commonly referred to as "Log4Shell" in various blogs and reports. Versions of the library said to be affected are versions Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0. Subsequently the following additional Log4j vulnerabilities CVE-2021-45105, CVE-2021-45046 and CVE-2021-44832 have been published.
Veracode has assessed the impact that these vulnerabilities and their associated exploits may have on our technology stack, as multiple Veracode products incorporate Apache Log4j. This assessment includes surveying key third-party service providers in our supply chain to confirm what level of exposure this vulnerability may have on the products that we use.
Veracode has taken appropriate action to mitigate risk exposure to our software and solutions and is prepared to take further action as new information around this vulnerability and its exploits come to light.
We have reviewed our logs and detection infrastructure and have not discovered evidence of exploitation in our environment at this time.
At Veracode, security is job number one, and trust is our greatest asset. We secure our software supply chain with multiple layers of defense measures, improving our security posture daily to ensure Veracode does not become a vector of attack. We appreciate your patience and understanding as Veracode continues to monitor and research potential exploits and vulnerabilities associated with this finding and will take action accordingly.
Please see Log4j Frequently Asked Questions for additional details.
.png)