tomolimo / ticketcleaner

Home for Ticket Cleaner GLPI plugin
8 stars 2 forks source link

vulnerability Log4Shell ? #24

Closed FRANCOIS50 closed 2 years ago

FRANCOIS50 commented 2 years ago

Glpi version 9.2.4 Plugin resources version 2.1.0 Good morning I have a Question: Is the plugin vulnerable to Log4shell (CVE-2021-44228)?

Thank you in advance for your answer

Regards

tomolimo commented 2 years ago

Hello @FRANCOIS50 I cannot say in details, but for me as soon as your web configuration doesn't use this log4j module, then it is free from the threat. So you have to check your web server installation. Thank you, Regards, Tomolimo

FRANCOIS50 commented 2 years ago

Ok thanks for your answer