Issue
A vulnerability was discovered in Apache Log4j1.x. Does this vulnerability affect Unified Workspace? If so, how do we go about mitigation of the vulnerability?
CVE-2021-4104
Solution
Unified Workspace does use Log4J 1.2.16.
This vulnerability ONLY affects applications which are specifically configured to use JMSAppender, which is not the default, or when the attacker has write access to the Log4j configuration for adding JMSAppender to the attacker's JMS Broker.With Unified Workspace, JMSAppender is not configured for use, and the only access to configure it for use, would require access to the server, or it's file system. Therefore Unified Workspace is NOT susceptible to this vulnerability.
Our developers, however, are currently working on upgrading Log4J to the most current release, in the next release of Unified Workspace.
UPDATE:
Log4J has been updated in Unified Workspace version 7.0.1.41.