
JavedM (Veracode, Inc.) asked a question.
Veracode Responses as of 02/17/2022 10:30 PM ET
Q: Q: Is Veracode ISM Endpoint impacted?
- Version 22.1.10 is available for download from The Veracode Help Center. The ISM Endpoint Version 22.1.10 has been updated to use Log4j version 2.17.1. This update addresses the vulnerabilities associated with log4j 2.15, 2.16 and 2.17.
Q: Is Veracode Integration for Jira Cloud impacted?
- 1.1.3-AC is available in the Atlassian Marketplace and addresses CVE-2021-44228 and CVE-2021-45046. This update should be automatically applied to your environment by Atlassian. Your Jira admin should be able to verify the installed version.
Q: Is Veracode Integration for Jira Server impacted?
- The Veracode Integration for Jira Server does not include log4j and is not vulnerable to CVE-2021-44228 or CVE-2021-45046.
Q: Is Veracode Integration for Jira Data Center impacted?
- The Veracode Integration for Jira Data Center does not include log4j and is not vulnerable to CVE-2021-44228 or CVE-2021-45046.
Q: Is Veracode Integration for TeamCity impacted?
- The Veracode Integration for TeamCity does not include log4j and is not vulnerable to CVE-2021-44228 or CVE-2021-45046.
Q: Is Veracode Static Visual Studio Extension impacted?
- The Veracode Static Visual Studio Extension does not include log4j and is not vulnerable to CVE-2021-44228 or CVE-2021-45046.
Q: Is Veracode Integration for Greenlight Visual Studio Extension impacted?
- The Veracode Greenlight Visual Studio Extension does not include log4j and is not vulnerable to CVE-2021-44228 or CVE-2021-45046.
Q: Is Veracode Greenlight VS Code Extension impacted?
- The Veracode Greenlight VS Code Extension does not include log4j and is not vulnerable to CVE-2021-44228 or CVE-2021-45046.
Q: Is the Veracode Greenlight Eclipse Plugin impacted?
- Version 2.9.1 is available in the Eclipse Marketplace and addresses CVE-2021-44228 and CVE-2021-45046. Customers should ensure they have updated to this release or newer. You can view your current version by navigating to Main Menu -> Veracode Greenlight -> About
Q: Is the Veracode Greenlight IntelliJ impacted?
- Version 1.8.1 is available in the JetBrains Marketplace and addresses CVE-2021-44228 and CVE-2021-45046. Customers should ensure they have updated to this release or newer. You can view your current version by navigating to Main Menu- > Tools -> Veracode Greenlight -> About
Q: Are the Veracode plug-ins and/or integrations impacted?
- All Veracode plug-ins and integrations identified to date as to running a vulnerable version of Log4j have been updated and made available in the third-party marketplaces we distribute to and direct from Veracode at the Integrations page on Veracode Community.
How can I reach out to Veracode?
- Please see our Log4j Vulnerability Resources page
- Veracode Security and Support teams are also available to respond to customer inquiries. Additional methods to contact Veracode are listed below:
§ US: 1-877-837-2203
§ UK: +44 (0)20 3761 5501
Email: support@veracode.com
.png)