couchbase / docker

Dockerfiles and configuration scripts for the Docker Hub Official Couchbase images
143 stars 154 forks source link

CVE-2021-44228 #168

Closed ghost closed 2 years ago

ghost commented 2 years ago

Docker blog suggests that Couchbase is affected: A number of the Docker Official images do contain the vulnerable versions of Log4j 2. The ones that we believe may contain vulnerable versions of Log4j 2, at the time of publishing this blog: couchbase https://www.docker.com/blog/apache-log4j-2-cve-2021-44228/

Could this be confirmed/denied please.

We're currently using the community-6.6.0 version.

ceejatec commented 2 years ago

Couchbase community edition is not affected, so you're OK.

ghost commented 2 years ago

Thanks ceejatec