
SAddagada213564 (Community Member) asked a question.
we have detected an older version of log4j - 1.2.17 in Veracode ISM(Internal Scanning Management) installation folder on our build server. We have this installed ISM on one of our On-prem servers which is not exposed to external network to allow access to our website for dynamic analysis.
Please let us know if we need to uninstall or get an updated installed that include patch for this vulnerability.
.png)
Hello @SAddagada213564 (Community Member) ,
If you are using Log4j 1.x, you are impacted by this vulnerability and highly suggest downloading and upgrading to the latest Log4j mitigated version 2.16.0. We have a blog, Analysis and Remediation Guidance to the Log4j Zero-Day RCE (CVE-2021-44228) Vulnerability that has instructions on how to upgrade and more details about how Veracode is addressing this vulnerability.
Jason
Veracode Support Engineer
Jason,
I am referring to the DAST Veracode agent(ISM) on our build server having an older version of log4j and trying to find if we need to uninstall or which version of agent has veracode applied the fix.
@SAddagada213564 (Community Member) ,
I checked with one of our senior engineers and they informed me that we currently don't support log4j with Dynamic Analysis but only with Software Composition Analysis at this time.
Jason
Veracode Support Engineer.
Hi Jason,
The question was about the ISM agent provided by Veracode.
Would Veracode provide an updated version as it is using log4j ?
Thanks.
@MDurand602679 (Community Member) ,
Veracode has determined that the ISM endpoint is not vulnerable to CVE-2021-44228. However, the software does contain the older 1.2.17 version of log4j. Veracode is planning to issue a patch in the immediate future that will upgrade log4j to the latest 2.16.0 version of the library.
Veracode recommends ensuring that you run the ISM service on a dedicated host with appropriate access controls, and that you use the default configurations recommended in the installation procedure on the Help Center in order to ensure the ISM endpoint is running with only the required privileges
Jason
Veracode Support Engineer