Checkmk is not affected by Log4j (CVE-2021-44228)

Checkmk is not affected by Log4j (CVE-2021-44228)

A critical Log4j vulnerability (CVE-2021-44228) affecting versions 2.0 to 2.14.1 was disclosed on December 9, 2021.

LAST TESTED ON CHECKMK 2.3.0P1

Table of Contents

Problem

Log4j is an open-source, Java-based logging utility widely used by enterprise applications and cloud services.

A remote attacker could take control of the affected system by utilizing this vulnerability.

Solution

Checkmk is aware of the vulnerability and has completed verification that this issue does not impact Checkmk itself and the Checkmk appliance.