Vulnerability in log4j

Forum for discussing PicoScope version 6 (non-automotive version)
Post Reply
Julian94
Newbie
Posts: 0
Joined: Fri Dec 17, 2021 8:52 am

Vulnerability in log4j

Post by Julian94 »

Hello everyone,

An IT security service provider's blog [LUN2021] reports vulnerability CVE-2021-44228 [MIT2021] in log4j versions 2.0 through 2.14.1, which may allow attackers to execute their own program code on the target system and compromise the server. This danger exists when log4j is used to log an attacker-controlled string, such as HTTP User Agent the fields in a web application.

Is the software “PicoScope 6” affected from this problem?

Thank you in advance.

Best regards,
Julian Zoller

Martyn
Site Admin
Site Admin
Posts: 4501
Joined: Fri Jun 10, 2011 8:15 am
Location: St. Neots

Re: Vulnerability in log4j

Post by Martyn »

We do not use log4j
Martyn
Technical Support Manager

Post Reply