javamelody / jira-confluence-javamelody

JavaMelody plugin for JIRA, Confluence or Bamboo
Apache License 2.0
13 stars 6 forks source link

Is the JavaMelody Monitoring Plugin affected by the Apache log4j Vulnerability CVE-2021-44228? #17

Closed chris-oshea closed 2 years ago

chris-oshea commented 2 years ago

Hi team, I hope you are doing well. On behalf of a customer, I have been tasked with asking if the JavaMelody Monitoring Plugin is affected by the Apache log4j Vulnerability CVE-2021-44228.

If this is the case, we would need to react promptly. Thanks in advance.

Best regards, Christopher

evernat commented 2 years ago

The javamelody monitoring plugin for JIRA/Confluence/Bamboo/Bitbucket is not affected by log4j vulnerabilities, because it does not include log4j.

See the security advisory for javamelody if you need more information: https://groups.google.com/g/javamelody/c/NqQy8rTTC6U