<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Log4j and log4j2 library  vulnerability]]></title><description><![CDATA[<p dir="auto">I'm not sure if you guys are tracking but unauthenticated RCE exploit just got dropped and is being exploited in the wild for log4j and log4j2 library.<br />
This is used in a ton of products from apache struts to elasticsearch as the default logging framework.<br />
Does cloudron use this and if so when can we get a patch?</p>
]]></description><link>https://forum.cloudron.io/topic/6153/log4j-and-log4j2-library-vulnerability</link><generator>RSS for Node</generator><lastBuildDate>Sat, 11 Jul 2026 18:13:46 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/6153.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 10 Dec 2021 19:53:55 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Wed, 29 Dec 2021 01:39:08 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> ah i didnt even notice bevause of all the 4j notices my eyes where too open <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f436.png?v=95dae3ecbe4" class="not-responsive emoji emoji-android emoji--dog" style="height:23px;width:auto;vertical-align:middle" title=":dog:" alt="🐶" /></p>
<p dir="auto">thx for looking at this anyway</p>
]]></description><link>https://forum.cloudron.io/post/41008</link><guid isPermaLink="true">https://forum.cloudron.io/post/41008</guid><dc:creator><![CDATA[3gal]]></dc:creator><pubDate>Wed, 29 Dec 2021 01:39:08 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Tue, 28 Dec 2021 13:27:20 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/3gal" aria-label="Profile: 3gal">@<bdi>3gal</bdi></a> neo4j and log4j are different. the former is a database and the latter is logging library. Kutt anyway is written in typescript and not affected by log4j issue.</p>
]]></description><link>https://forum.cloudron.io/post/40996</link><guid isPermaLink="true">https://forum.cloudron.io/post/40996</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Tue, 28 Dec 2021 13:27:20 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Mon, 27 Dec 2021 14:26:58 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> I found log4j2 libary usage in kutt (urlshortener)</p>
<p dir="auto">Standard config:</p>
<pre><code># ONLY NEEDED FOR MIGRATION !!1!
# Neo4j database credential details
NEO4J_DB_URI=bolt://localhost
NEO4J_DB_USERNAME=
NEO4J_DB_PASSWORD=
</code></pre>
<p dir="auto">changed to this without errors:</p>
<pre><code># ONLY NEEDED FOR MIGRATION !!1!
# Neo4j database credential details
#NEO4J_DB_URI=bolt://localhost
#NEO4J_DB_USERNAME=neo4j
#NEO4J_DB_PASSWORD=BjEphmupAf1D5pDD
</code></pre>
<p dir="auto">Is there anything else to do?<br />
Is that even a issue?</p>
]]></description><link>https://forum.cloudron.io/post/40965</link><guid isPermaLink="true">https://forum.cloudron.io/post/40965</guid><dc:creator><![CDATA[3gal]]></dc:creator><pubDate>Mon, 27 Dec 2021 14:26:58 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Sun, 26 Dec 2021 13:17:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mastadamus" aria-label="Profile: mastadamus">@<bdi>mastadamus</bdi></a> thanks alot, will try to implement this &amp; will report under your post <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=95dae3ecbe4" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>
]]></description><link>https://forum.cloudron.io/post/40934</link><guid isPermaLink="true">https://forum.cloudron.io/post/40934</guid><dc:creator><![CDATA[rmdes]]></dc:creator><pubDate>Sun, 26 Dec 2021 13:17:16 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Fri, 24 Dec 2021 15:35:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/rmdes" aria-label="Profile: rmdes">@<bdi>rmdes</bdi></a> <a href="https://forum.cloudron.io/topic/6224/crowdsec-install-guide-for-cloudron-purposes">https://forum.cloudron.io/topic/6224/crowdsec-install-guide-for-cloudron-purposes</a></p>
]]></description><link>https://forum.cloudron.io/post/40907</link><guid isPermaLink="true">https://forum.cloudron.io/post/40907</guid><dc:creator><![CDATA[Mastadamus]]></dc:creator><pubDate>Fri, 24 Dec 2021 15:35:12 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Thu, 23 Dec 2021 15:35:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/rmdes" aria-label="Profile: rmdes">@<bdi>rmdes</bdi></a> I'll put one together later tonight.</p>
]]></description><link>https://forum.cloudron.io/post/40860</link><guid isPermaLink="true">https://forum.cloudron.io/post/40860</guid><dc:creator><![CDATA[Mastadamus]]></dc:creator><pubDate>Thu, 23 Dec 2021 15:35:46 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Thu, 23 Dec 2021 11:32:07 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mastadamus" aria-label="Profile: mastadamus">@<bdi>mastadamus</bdi></a> do you have a step by step instructions to setup crowdsec in a cloudron context ?</p>
]]></description><link>https://forum.cloudron.io/post/40851</link><guid isPermaLink="true">https://forum.cloudron.io/post/40851</guid><dc:creator><![CDATA[rmdes]]></dc:creator><pubDate>Thu, 23 Dec 2021 11:32:07 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Sat, 18 Dec 2021 04:08:27 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mastadamus" aria-label="Profile: mastadamus">@<bdi>mastadamus</bdi></a> I'm happy to report that Crowdsec successfully responded to a log4j exploit scanner. If you set up your nginx log configuration per my post in support, and install the nginx collection as well as the log4j2 collection with an firewall iptable bouncer it will auto block any ip belonging to an attempt it parses out.</p>
<p dir="auto">crowdsec	crowdsecurity/apache_log4j2_cve-2021-44228	Ip	45.83.65.33			2021-12-17 07:55:25	2021-12-17 07:55:25</p>
]]></description><link>https://forum.cloudron.io/post/40692</link><guid isPermaLink="true">https://forum.cloudron.io/post/40692</guid><dc:creator><![CDATA[Mastadamus]]></dc:creator><pubDate>Sat, 18 Dec 2021 04:08:27 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Fri, 17 Dec 2021 19:11:30 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/rmdes" aria-label="Profile: rmdes">@<bdi>rmdes</bdi></a> good suggestion.</p>
]]></description><link>https://forum.cloudron.io/post/40679</link><guid isPermaLink="true">https://forum.cloudron.io/post/40679</guid><dc:creator><![CDATA[Mastadamus]]></dc:creator><pubDate>Fri, 17 Dec 2021 19:11:30 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Fri, 17 Dec 2021 19:10:56 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> min patch to rectify log4j2 issues is 2.16 .. 2.15 is affected by cvss 9.0 rce in some instances.</p>
]]></description><link>https://forum.cloudron.io/post/40678</link><guid isPermaLink="true">https://forum.cloudron.io/post/40678</guid><dc:creator><![CDATA[Mastadamus]]></dc:creator><pubDate>Fri, 17 Dec 2021 19:10:56 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Fri, 17 Dec 2021 15:42:46 GMT]]></title><description><![CDATA[<p dir="auto">I am aware of solr being detected by the static analyzers (the marketplace images complain about the same). solr is used internally for full text search in the mail container. It's not on by default and it's also not exposed outside the internal docker network (so not exposed to outside world).</p>
<p dir="auto">Still, we will update the mail container. Solr only put out a new release yesterday which update log4j.</p>
]]></description><link>https://forum.cloudron.io/post/40662</link><guid isPermaLink="true">https://forum.cloudron.io/post/40662</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Fri, 17 Dec 2021 15:42:46 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Fri, 17 Dec 2021 15:16:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/necrevistonnezr" aria-label="Profile: necrevistonnezr">@<bdi>necrevistonnezr</bdi></a> ah ok, then this is fine. It is not exposed or anything.</p>
]]></description><link>https://forum.cloudron.io/post/40656</link><guid isPermaLink="true">https://forum.cloudron.io/post/40656</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Fri, 17 Dec 2021 15:16:54 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Fri, 17 Dec 2021 15:15:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> The only SOLR instance is the Cloudron internal mail indexing, in my case.</p>
]]></description><link>https://forum.cloudron.io/post/40654</link><guid isPermaLink="true">https://forum.cloudron.io/post/40654</guid><dc:creator><![CDATA[necrevistonnezr]]></dc:creator><pubDate>Fri, 17 Dec 2021 15:15:06 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Fri, 17 Dec 2021 14:24:57 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/brutalbirdie" aria-label="Profile: brutalbirdie">@<bdi>brutalbirdie</bdi></a> just because the library is used, does not mean the app is actually vulnerable. In either case all we can really do from our side is to closely track upstream releases during such times and release new app packages asap. We usually can't really patch the upstream apps easily. In this case it seem to be prometheus related? <a class="plugin-mentions-user plugin-mentions-a" href="/user/necrevistonnezr" aria-label="Profile: necrevistonnezr">@<bdi>necrevistonnezr</bdi></a> do you know to which app those layers in your case are related to?</p>
]]></description><link>https://forum.cloudron.io/post/40649</link><guid isPermaLink="true">https://forum.cloudron.io/post/40649</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Fri, 17 Dec 2021 14:24:57 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Fri, 17 Dec 2021 11:29:35 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a>  <strong>ping</strong><br />
Can you check that out?</p>
]]></description><link>https://forum.cloudron.io/post/40644</link><guid isPermaLink="true">https://forum.cloudron.io/post/40644</guid><dc:creator><![CDATA[BrutalBirdie]]></dc:creator><pubDate>Fri, 17 Dec 2021 11:29:35 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Fri, 17 Dec 2021 11:06:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> I ran <a href="https://github.com/mergebase/log4j-detector" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/mergebase/log4j-detector</a> today and it seems that at least SOLR is vulnerable(?)</p>
<pre><code>/proc/5961/task/9300/cwd/lib/ext/log4j-core-2.14.1.jar contains Log4J-2.x   &gt;= 2.10.0 _VULNERABLE_ :-(
/var/lib/docker/overlay2/32ab0d12f3342918d0ffea4a1392cb760f852f9bf0a219c682dd366ff26e72bc/diff/usr/share/java/log4j-1.2-1.2.17.jar contains Log4J-1.x   &lt;= 1.2.17 _OLD_ :-|
/var/lib/docker/overlay2/5bb4ce30d32c6760fe21e98ab6f98651bf9591e83ab2385f0a4833ee5ef0c979/diff/app/code/solr/contrib/prometheus-exporter/lib/log4j-core-2.14.1.jar contains Log4J-2.x   &gt;= 2.10.0 _VULNERABLE_ :-(
/var/lib/docker/overlay2/5bb4ce30d32c6760fe21e98ab6f98651bf9591e83ab2385f0a4833ee5ef0c979/diff/app/code/solr/server/lib/ext/log4j-core-2.14.1.jar contains Log4J-2.x   &gt;= 2.10.0 _VULNERABLE_ :-(
/var/lib/docker/overlay2/f8ed382cc2590afd6189335f84aaf0f561811a5165dbf58191be61048c5312f5/merged/app/code/solr/contrib/prometheus-exporter/lib/log4j-core-2.14.1.jar contains Log4J-2.x   &gt;= 2.10.0 _VULNERABLE_ :-(
/var/lib/docker/overlay2/f8ed382cc2590afd6189335f84aaf0f561811a5165dbf58191be61048c5312f5/merged/app/code/solr/server/lib/ext/log4j-core-2.14.1.jar contains Log4J-2.x   &gt;= 2.10.0 _VULNERABLE_ :-(
</code></pre>
]]></description><link>https://forum.cloudron.io/post/40642</link><guid isPermaLink="true">https://forum.cloudron.io/post/40642</guid><dc:creator><![CDATA[necrevistonnezr]]></dc:creator><pubDate>Fri, 17 Dec 2021 11:06:49 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Thu, 16 Dec 2021 17:13:39 GMT]]></title><description><![CDATA[<p dir="auto">"Log4j 2.15.0 and previously suggested mitigations may not be enough" - <a href="https://isc.sans.edu/diary/Log4j+2.15.0+and+previously+suggested+mitigations+may+not+be+enough/28134" target="_blank" rel="noopener noreferrer nofollow ugc">https://isc.sans.edu/diary/Log4j+2.15.0+and+previously+suggested+mitigations+may+not+be+enough/28134</a></p>
]]></description><link>https://forum.cloudron.io/post/40610</link><guid isPermaLink="true">https://forum.cloudron.io/post/40610</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Thu, 16 Dec 2021 17:13:39 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Mon, 13 Dec 2021 09:51:29 GMT]]></title><description><![CDATA[<p dir="auto">This tool is also neat, with or without cloudron context : <a href="https://github.com/fullhunt/log4j-scan" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/fullhunt/log4j-scan</a></p>
]]></description><link>https://forum.cloudron.io/post/40425</link><guid isPermaLink="true">https://forum.cloudron.io/post/40425</guid><dc:creator><![CDATA[rmdes]]></dc:creator><pubDate>Mon, 13 Dec 2021 09:51:29 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Mon, 13 Dec 2021 09:47:49 GMT]]></title><description><![CDATA[<p dir="auto">Docker Scan should allow us to scan cloudron containers if any doubt remains :<br />
<a href="https://www.docker.com/blog/apache-log4j-2-cve-2021-44228/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.docker.com/blog/apache-log4j-2-cve-2021-44228/</a></p>
<p dir="auto">edit : <a href="https://github.com/docker/scan-cli-plugin/releases/tag/v0.11.0" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/docker/scan-cli-plugin/releases/tag/v0.11.0</a></p>
]]></description><link>https://forum.cloudron.io/post/40424</link><guid isPermaLink="true">https://forum.cloudron.io/post/40424</guid><dc:creator><![CDATA[rmdes]]></dc:creator><pubDate>Mon, 13 Dec 2021 09:47:49 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Mon, 13 Dec 2021 09:12:06 GMT]]></title><description><![CDATA[<p dir="auto">Here's a maintained list with log4j advisories: <a href="https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592" target="_blank" rel="noopener noreferrer nofollow ugc">https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592</a></p>
<p dir="auto">log4j detector: <a href="https://github.com/mergebase/log4j-detector" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/mergebase/log4j-detector</a></p>
<p dir="auto">"Vaccine": <a href="https://www.bleepingcomputer.com/news/security/researchers-release-vaccine-for-critical-log4shell-vulnerability/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/researchers-release-vaccine-for-critical-log4shell-vulnerability/</a></p>
]]></description><link>https://forum.cloudron.io/post/40422</link><guid isPermaLink="true">https://forum.cloudron.io/post/40422</guid><dc:creator><![CDATA[necrevistonnezr]]></dc:creator><pubDate>Mon, 13 Dec 2021 09:12:06 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Sun, 12 Dec 2021 16:19:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/privsec" aria-label="Profile: privsec">@<bdi>privsec</bdi></a> I tested nextcloud with a log4j2 testing tool from huntress and I couldn't get it to callback to the ldap server so i think its gtg.</p>
]]></description><link>https://forum.cloudron.io/post/40399</link><guid isPermaLink="true">https://forum.cloudron.io/post/40399</guid><dc:creator><![CDATA[Mastadamus]]></dc:creator><pubDate>Sun, 12 Dec 2021 16:19:42 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Sat, 11 Dec 2021 21:22:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/privsec" aria-label="Profile: privsec">@<bdi>privsec</bdi></a> I'm already receiving exploit/scan attempts inbound. No successful exploits. I believe nothing in my cloudron stack uses it. I can't find any confirmation nextcloud does. If you find something i'd love it asap.</p>
]]></description><link>https://forum.cloudron.io/post/40392</link><guid isPermaLink="true">https://forum.cloudron.io/post/40392</guid><dc:creator><![CDATA[Mastadamus]]></dc:creator><pubDate>Sat, 11 Dec 2021 21:22:36 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Sat, 11 Dec 2021 20:14:48 GMT]]></title><description><![CDATA[<p dir="auto">Nextcloud, mincraft, use this, right?</p>
]]></description><link>https://forum.cloudron.io/post/40391</link><guid isPermaLink="true">https://forum.cloudron.io/post/40391</guid><dc:creator><![CDATA[privsec]]></dc:creator><pubDate>Sat, 11 Dec 2021 20:14:48 GMT</pubDate></item><item><title><![CDATA[Reply to Log4j and log4j2 library  vulnerability on Sat, 11 Dec 2021 17:59:59 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jdaviescoates" aria-label="Profile: jdaviescoates">@<bdi>jdaviescoates</bdi></a> Its heavily weaponized. Like if you have an app thats affected chances are its going to get popped if you leave it unmitigated.  Broad array of actors are exploiting it.. from coin miners to more advanced threats. Grey noise is tracking the IP's associated with the threat campaigns and right now they are numerous.</p>
]]></description><link>https://forum.cloudron.io/post/40388</link><guid isPermaLink="true">https://forum.cloudron.io/post/40388</guid><dc:creator><![CDATA[Mastadamus]]></dc:creator><pubDate>Sat, 11 Dec 2021 17:59:59 GMT</pubDate></item></channel></rss>