VMware Cloud Community
tomas_strand
Enthusiast
Enthusiast

Apache Log4j2 Remote Code Execution Vulnerability Alert

https://arstechnica.com/information-technology/2021/12/minecraft-and-other-apps-face-serious-threat-...

Anyone know if this is something that impacts Cloud director. And so. How to/where to  pass log4j2.formatMsgNoLookups=true in the configuration?

 

CVE-2021-44228

 

 

0 Kudos
5 Replies
abochmann
Contributor
Contributor

I've been wondering about the same thing - nothing to be seen in any of the log4j communication about Cloud Director, even though the system clearly runs a Java stack, and is explicitly designed to be made accessible from the public Internet (in contrast to most other products).

0 Kudos
abochmann
Contributor
Contributor

It seems Cloud Director is "not impacted": https://kb.vmware.com/s/article/87068?lang=en_US

0 Kudos
SMcClure1
VMware Employee
VMware Employee

For the latest information regardingCVE-2021-44228 - Remote code execution vulnerability via Apache Log4j  - Please go here https://www.vmware.com/security/advisories/VMSA-2021-0028.html 

0 Kudos
scott28tt
VMware Employee
VMware Employee

A moderator may move this thread to the area for vCD.

 


-------------------------------------------------------------------------------------------------------------------------------------------------------------

Although I am a VMware employee I contribute to VMware Communities voluntarily (ie. not in any official capacity)
VMware Training & Certification blog
0 Kudos
SMcClure1
VMware Employee
VMware Employee

Content is being update frequently  

For Tanzu you can find updated KBs and Answers here

For VMware Core you can find updates KBs and Answers here

0 Kudos