sanger-pathogens / Artemis

Artemis is a free genome viewer and annotation tool that allows visualization of sequence features and the results of analyses within the context of the sequence, and its six-frame translation
http://sanger-pathogens.github.io/Artemis
Other
236 stars 76 forks source link

log4j vulnerability #326

Closed kb529 closed 2 years ago

kb529 commented 2 years ago

As you may already be aware, a log4j 2.x vulnerability was identified last week (https://nvd.nist.gov/vuln/detail/CVE-2021-44228). Using the scanning tool from https://github.com/mergebase/log4j-detector , it appears that Artemis v18.1 uses an impacted version of log4j.

log4j-detector output: artemis\act.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) VULNERABLE :-( artemis\artemis.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) VULNERABLE :-( artemis\bamview.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) VULNERABLE :-( artemis\dnaplotter.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) VULNERABLE :-(

If this is correct, are there any plans to update Artemis to use a patched version of log4j? Thank you.

lifesci-IT commented 2 years ago

Could somebody acknowledge this issue? - we are currently blocking all our users from access to this app until it is patched.

ensignvorik commented 2 years ago

Ditto, appreciate this is a community app, have however had to tell Academics we can't keep this app on our systems.

kpepper commented 2 years ago

Issue is fixed in the latest v18.2.0 release, which is using log4j 2.17.2.