<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Upgrade ACS 7.0.0 to 7.0.1 has LOG4j vulnerabilities in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/upgrade-acs-7-0-0-to-7-0-1-has-log4j-vulnerabilities/m-p/130187#M35199</link>
    <description>&lt;P&gt;Hello, I have a stand alone install of Alfresco Community Edition 7.0.0 I performed via ansible and noticed ~webapps/_vti_bin.war has log4j 1.2.17 inside it which might be vulnerable (&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2019-17571" target="_blank" rel="noopener nofollow noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2019-17571&lt;/A&gt;).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I'f _vti_bin.war was been updated in 7.0.1 I'd like to upgrade but the upgrade path reads like I need to do a fresh ACS7.0.1 install and transfer my 7.0.0 content store to it?&amp;nbsp;&amp;nbsp;&amp;nbsp; Am I reading this wrong?&lt;/P&gt;</description>
    <pubDate>Mon, 14 Feb 2022 18:51:57 GMT</pubDate>
    <dc:creator>michaelzietlow</dc:creator>
    <dc:date>2022-02-14T18:51:57Z</dc:date>
    <item>
      <title>Upgrade ACS 7.0.0 to 7.0.1 has LOG4j vulnerabilities</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/upgrade-acs-7-0-0-to-7-0-1-has-log4j-vulnerabilities/m-p/130187#M35199</link>
      <description>&lt;P&gt;Hello, I have a stand alone install of Alfresco Community Edition 7.0.0 I performed via ansible and noticed ~webapps/_vti_bin.war has log4j 1.2.17 inside it which might be vulnerable (&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2019-17571" target="_blank" rel="noopener nofollow noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2019-17571&lt;/A&gt;).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I'f _vti_bin.war was been updated in 7.0.1 I'd like to upgrade but the upgrade path reads like I need to do a fresh ACS7.0.1 install and transfer my 7.0.0 content store to it?&amp;nbsp;&amp;nbsp;&amp;nbsp; Am I reading this wrong?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 18:51:57 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/upgrade-acs-7-0-0-to-7-0-1-has-log4j-vulnerabilities/m-p/130187#M35199</guid>
      <dc:creator>michaelzietlow</dc:creator>
      <dc:date>2022-02-14T18:51:57Z</dc:date>
    </item>
    <item>
      <title>ACS7.0.0-7.1.1 has Multiple Apache Log4j Vulnerabilities and should be patched!</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/upgrade-acs-7-0-0-to-7-0-1-has-log4j-vulnerabilities/m-p/130188#M35200</link>
      <description>&lt;DIV&gt;&lt;P&gt;**UPDATE**&lt;BR /&gt;&amp;nbsp; I upgraded to the latest Community 7.1.1 zip and I ran a Tenable scan agains my content-services-7.1.0.1.&amp;nbsp; It still reports the following log4j vulnerability.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;H3 id="toc-hId-1477682813"&gt;Synopsis&lt;/H3&gt;&lt;DIV class=""&gt;&lt;P&gt;The logging library running inside ~/web-server/webapps/_vti_bin.war is version&amp;nbsp;1.2.17 from 2016. It has multiple log4j vulnerabilities that should be patched.&lt;/P&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;H3 id="toc-hId--1074474148"&gt;Description&lt;/H3&gt;&lt;DIV class=""&gt;&lt;P&gt;According to its self-reported version number(1.2.17), the installation of Apache Log4j in ACS 7.1.x is no longer supported. Log4j reached its end of life prior to 2016. Additionally, Log4j 1.x is affected by multiple vulnerabilities, including :&lt;BR /&gt;...&lt;BR /&gt;...&lt;BR /&gt;~EDITED~we dont need to describe how to compromise this version log4j here~EDITED~&lt;/P&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 27 Apr 2022 20:10:13 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/upgrade-acs-7-0-0-to-7-0-1-has-log4j-vulnerabilities/m-p/130188#M35200</guid>
      <dc:creator>michaelzietlow</dc:creator>
      <dc:date>2022-04-27T20:10:13Z</dc:date>
    </item>
  </channel>
</rss>

