Page 1 of 1

Apache Java Log4j2/Log4Shell zero-day vulnerability

Posted: Tue Dec 14, 2021 12:32 pm
by michael85
Dear FFAStrans developer,

can you say anything if FFAStrans, the webinterface or any other component of your software is affected by this vulnerability?
and do you use Java at all?
This is a very high prioritized topic in the company where I work for.

You can find my more details about the vulnerability here: https://nvd.nist.gov/vuln/detail/CVE-2021-44228

Best regards
Michael

Re: Apache Log4j2/Log4Shell zero-day vulnerability

Posted: Tue Dec 14, 2021 3:04 pm
by emcodem
Hi michael,

good question, i already thought about posting that info here.
We can confirm that FFAStrans and all software components that come with the download are NOT affected (no java is used). Same for the Webinterface download and all it's components as well as all downloadable content on ffastrans.com and subpages.