VMware Cloud Community
bmurray2
Contributor
Contributor

In Horizon 2111, is log4j mitigated by 8.4.0 build - 19067837 ?

Our ISO is still complaining that our Horizon servers are vulnerable, according to Tenable.  It's detecting log4j-core-2.16.0.jar, which indeed exists in path C:\Program Files\VMware\VMware View\Server\messagebus\kernel\sys$authentication on our fully patched connection servers.  Can someone explain how exactly this build mitigates the threat?  A pointer to an official doc from VMWare would be the best source, but I've yet to stumble across it.

Reply
0 Kudos
0 Replies