<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CVE-2021-44228 in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/cve-2021-44228/m-p/144256#M38282</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/52373"&gt;@maxodoble&lt;/A&gt;&amp;nbsp;-&lt;/P&gt;
&lt;P&gt;You can also find a post here on the Hub about it:&amp;nbsp;&lt;A href="https://hub.alfresco.com/t5/alfresco-content-services-blog/apache-log4j-vulnerability-cve-2021-44228/ba-p/310661" target="_blank" rel="noopener nofollow noreferrer"&gt;https://hub.alfresco.com/t5/alfresco-content-services-blog/apache-log4j-vulnerability-cve-2021-44228/ba-p/310661&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We'll also be providing extra updates as we get them from Hyland's security teams.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Amanda&lt;/P&gt;</description>
    <pubDate>Tue, 14 Dec 2021 20:24:49 GMT</pubDate>
    <dc:creator>amanda_roberts</dc:creator>
    <dc:date>2021-12-14T20:24:49Z</dc:date>
    <item>
      <title>CVE-2021-44228</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/cve-2021-44228/m-p/144253#M38279</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;is anybody aware of the consequences of this nasty log4j vulnerability for alfresco community versions?&lt;/P&gt;&lt;P&gt;a very quick look shows that log4j v 1.2.17 is used in alfresco community (repo and share), and not directly hit by CVE-2021-44228 (seems to be versions &amp;gt;2 only), but then the question arises why such an old (and&amp;nbsp; unsupported since 2015?) version of log4j is being used happily here in late 2021.&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Max&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 13:42:36 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/cve-2021-44228/m-p/144253#M38279</guid>
      <dc:creator>maxodoble</dc:creator>
      <dc:date>2021-12-12T13:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/cve-2021-44228/m-p/144254#M38280</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/apache/logging-log4j2/pull/608#issuecomment-990494126" target="_blank" rel="nofollow noopener noreferrer"&gt;https://github.com/apache/logging-log4j2/pull/608#issuecomment-990494126&lt;/A&gt;&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;applications using Log4j 1.x may be impacted if their configuration uses JNDI. However, the risk is much lower.&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;Does anybody now a quick fix to update Log4j ?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 08:19:33 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/cve-2021-44228/m-p/144254#M38280</guid>
      <dc:creator>Renesto</dc:creator>
      <dc:date>2021-12-13T08:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/cve-2021-44228/m-p/144255#M38281</link>
      <description>&lt;DIV data-contents="true"&gt;
&lt;DIV class="" data-block="true" data-editor="3mcf7" data-offset-key="fpe3l-0-0"&gt;
&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr" data-offset-key="d02bo-0-0"&gt;&lt;SPAN data-offset-key="fpe3l-2-0"&gt;Take a look at &lt;/SPAN&gt;&lt;SPAN style="color: #1d9bf0;"&gt;&lt;SPAN data-offset-key="cha9f-0-0"&gt;&lt;A href="https://community.hyland.com/en/blog/posts/82098-apache-log4j-security-advisory" target="_blank" rel="nofollow noopener noreferrer"&gt;https://community.hyland.com/en/blog/posts/82098-apache-log4j-security-advisory&lt;/A&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-offset-key="d02bo-0-0"&gt;(login required).&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="" data-block="true" data-editor="3mcf7" data-offset-key="d02bo-0-0"&gt;
&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr" data-offset-key="d02bo-0-0"&gt;&lt;SPAN data-offset-key="d02bo-0-0"&gt;No impact has been determined for latest &lt;/SPAN&gt;&lt;SPAN style="color: #1d9bf0;"&gt;&lt;SPAN data-offset-key="d02bo-1-0"&gt;&lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/67382"&gt;@alfresco&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-offset-key="d02bo-2-0"&gt; releases!&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 13 Dec 2021 09:18:32 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/cve-2021-44228/m-p/144255#M38281</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2021-12-13T09:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/cve-2021-44228/m-p/144256#M38282</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/52373"&gt;@maxodoble&lt;/A&gt;&amp;nbsp;-&lt;/P&gt;
&lt;P&gt;You can also find a post here on the Hub about it:&amp;nbsp;&lt;A href="https://hub.alfresco.com/t5/alfresco-content-services-blog/apache-log4j-vulnerability-cve-2021-44228/ba-p/310661" target="_blank" rel="noopener nofollow noreferrer"&gt;https://hub.alfresco.com/t5/alfresco-content-services-blog/apache-log4j-vulnerability-cve-2021-44228/ba-p/310661&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We'll also be providing extra updates as we get them from Hyland's security teams.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Amanda&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 20:24:49 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/cve-2021-44228/m-p/144256#M38282</guid>
      <dc:creator>amanda_roberts</dc:creator>
      <dc:date>2021-12-14T20:24:49Z</dc:date>
    </item>
  </channel>
</rss>

