JavedM (Veracode, Inc.) asked a question.

Veracode's Log4j Remediation FAQ

 

Veracode Responses as of 01/31/2021 1:30 PM ET

 

Q: Has Veracode determined whether there is any impact to its organization?

  • Veracode has assessed the impact that this vulnerability and its associated exploits may have on our technology stack, as multiple Veracode products incorporate Apache Log4j. This assessment includes surveying our key third-party service providers to confirm what level of exposure this vulnerability may have on the products that we use. Veracode has taken appropriate action to mitigate risk exposure to our software and solutions and is prepared to take further action as new information around this vulnerability and its exploits comes to light. 

Q: Do you currently have assets running a vulnerable instance of Apache Log4j?

  • Based on the assessment performed to date Veracode applications that included versions of Apache Log4j impacted by CVE-2021-44228, CVE-2021-45046, CVE-2020-9488 and CVE-2021-45105 have been updated to at least Apache Log4j 2.17.0. Veracode has updated certain applications to Apache Log4j 2.17.1 and is in process of testing and applying the remediation for the remaining applications. 

Q: Is there any impact on your company’s ability to deliver services due to mitigation actions?

  • Veracode does not see a significant risk to our customer data or services at this time. Veracode has taken appropriate action to mitigate risk exposure to our software and solutions and is prepared to take further action as new information around this vulnerability and its exploits comes to light. 

Q: What actions has Veracode taken to detect and block malicious attempts to compromise your systems?

  • Veracode employs a set of security and networking tools that are designed to detect and block malicious attempts to compromise our systems. Such tools include web application firewalls (WAF), advanced endpoint protection, network ingress/egress filtering, and enhanced monitoring. 

Q: Have you identified any instances of active exploitation attempts?

  • We have reviewed our logs and detection infrastructure and have not discovered evidence of exploitation in our environment at this time. 

Q: Is the Veracode SCA Agent impacted?

  • The Veracode SCA Agent does not include log4j and is not vulnerable.

Q: Is the Veracode JAVA API Wrapper impacted?

  • The Veracode Java API Wrapper does not include log4j and is not vulnerable.

Q: Is the Veracode C# API Wrapper impacted?

  • The Veracode C# API Wrapper does not include log4j and is not vulnerable.

Q: Is the Veracode Artifactory Plugin impacted?

  • The Veracode Artifactory Plugin does not include log4j and is not vulnerable.

Q: Is the Veracode Azure DevOps Extension impacted?

  • The Veracode Azure DevOps Extension does not include log4j and is not vulnerable.

Q: Is the Veracode Static Eclipse Plugin impacted?

  • The Static Eclipse Plugin does not include log4j and is not vulnerable.

Q: Is the Veracode Static IntelliJ Plugin impacted?

  • The Static IntelliJ Plugin does not include log4j and is not vulnerable.

Q: Is Veracode for Jenkins impacted?

  • Veracode for Jenkins is not vulnerable to CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 or CVE-2021-44832. The current version is 21.9.16.0 and is available at the Jenkins Marketplace. Your Jenkins admin should be able to verify the currently installed version. 

Q: Is Veracode Pipeline Scan impacted?

  • Veracode Pipeline Scan is not vulnerable to CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 or CVE-2021-44832. The current version is 22.1.1 and is available from Docker Hub or the Veracode Downloads page

Q: Is the Veracode Agile Central Integration impacted?

  •  The Veracode Integration for CA Agile Central/Rally is now end-of-life and no longer supported. The plugin and documentation are no longer available. To avoid potential security vulnerabilities, Veracode strongly recommends that you uninstall this integration. To integrate with other ticketing systems, visit the Veracode Integrations Hub

 

For Part 2 of the FAQs, please click on the link here.

 

 


Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.