Skip to content

Log4J mitigations #43

Answered by jstanden
baknight1975 asked this question in Q&A
Discussion options

You must be logged in to vote

Hi Barry!

Thanks for asking. It will be useful to have a public statement here.

Cerb itself is PHP/HTML/Javascript, so it's not affected directly by log4j.

There aren't any Cerb Cloud production servers under our control with Java/JVM installed in any region, nor any internal services running in Java. We migrated all of that to Python and Node.js many years ago.

We did have an isolated staging server with Apache Tika (Java + log4j) installed for an earlier demo (automated document text extraction from XLS/PDF). That was taken offline last Friday. The machine didn't have any privileged access and had an inbound firewall preventing anyone from using it.

Upstream, Amazon Web Services may use…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by baknight1975
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants