cancel
Showing results for 
Search instead for 
Did you mean: 
CommunityJedi22
Community Manager
Community Manager

We are pleased to report that we completed the necessary patching of any systems where vulnerable versions of Log4j were identified in our applications. These instances are updated to Log4j 2.16 as of Dec 16, 2021,  Log4j 2.17 as of Dec 20, 2021, and Log4j 2.17.1 as of Jan 6, 2022.  This completes our mitigation efforts.

The majority of our applications have been protected against any attempted exploits of the Log4j vulnerability since Dec. 11, 2021, via our web application firewall(s). We also patched the threat-protection software on the physical firewalls protecting our core applications on Dec 15, 2021 to block any Log4j exploitation attempts. These added layers of protection are part of our defense-in-depth approach to securing our systems.

We continue to monitor for any updated information or subsequent changes that require attention.

We will provide future updates as needed.

Thank you

1WorldSync Security Team

Comments
azechman
New Contributor

My IT team is asking for some clarification.  The say 2.17 does not mitigate the issue and 2.17.1 does?  Are you able to verify that 2.17.1 is being used?

CommunityJedi22
Community Manager
Community Manager

Let me ask...

azechman
New Contributor

Have you heard anything in regards to this yet?

CommunityJedi22
Community Manager
Community Manager

Hello, yes, I made a few updates on here yesterday.  We explained further what we did.  Please take a look and let me know if you have any questions.  

Version history
Revision #:
6 of 6
Last update:
‎01-06-2022 03:17 PM
Updated by:
 
Contributors