Is CheckMK affected? - Log4j RCE Vulnerability

As many of you are probably aware, a major vulnerability was found in a Java logging package called logJ4. (huntress.com). A large number of products are affected including Apache to Ubiquiti Unifi Network Application (see article).

Is CheckMK using the log4j library and/or is it affected by this vulnerability?

Also, good luck to all the sysadmins out there patching everything.

No there is no Java inside here :smiley:
You can have a look at the source and all the included libraries here.

2 Likes

Hi jalf2,

Lars shared an official update about it today:

Cheers,
Faye

5 Likes

This topic was automatically closed 365 days after the last reply. New replies are no longer allowed. Contact an admin if you think this should be re-opened.