Joomla 3.10.3 susceptible for log4j zero day exploit? Topic is solved

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
Tom6293
Joomla! Apprentice
Joomla! Apprentice
Posts: 31
Joined: Mon May 21, 2018 4:00 pm

Joomla 3.10.3 susceptible for log4j zero day exploit?

Post by Tom6293 » Mon Dec 13, 2021 3:47 pm

Dear All,

Given the serious warnings about the recently discovered log4j zero day exploit, I am a bit concerned that my website running Joomla 3.10.3 might be at risk.

Does anyone know, if Joomla 3.10.3 is in principle at risk or not?
If so, are than any recommendations on how to deal with the current situation?

Thanks
Tom

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: Joomla 3.10.3 susceptible for log4j zero day exploit?

Post by mandville » Mon Dec 13, 2021 4:42 pm

ask your server host to patch it if used. your server software.
tell them to look at this apache release for server software.
https://logging.apache.org/log4j/2.x/security.html
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

Richard67
Joomla! Explorer
Joomla! Explorer
Posts: 270
Joined: Fri Sep 16, 2011 6:13 pm
Location: Germany
Contact:

Re: Joomla 3.10.3 susceptible for log4j zero day exploit?

Post by Richard67 » Mon Dec 13, 2021 4:55 pm

log4j is a logging library for Java (not Javascript) which is maintained by apache.org, but it has nothing to do with the apache web server.

That means Joomla is safe as long as you don't use a 3rd party extension which for some reason uses Oracle Java formerly Sun Java.

Tom6293
Joomla! Apprentice
Joomla! Apprentice
Posts: 31
Joined: Mon May 21, 2018 4:00 pm

Re: Joomla 3.10.3 susceptible for log4j zero day exploit?

Post by Tom6293 » Tue Dec 14, 2021 5:49 pm

Thanks mandville and Richard67,

You made my day :) .

Regards
Tom

Richard67
Joomla! Explorer
Joomla! Explorer
Posts: 270
Joined: Fri Sep 16, 2011 6:13 pm
Location: Germany
Contact:

Re: Joomla 3.10.3 susceptible for log4j zero day exploit?

Post by Richard67 » Tue Dec 14, 2021 5:57 pm

For completeness, here the official list of Apache products and if they are affected or not: https://blogs.apache.org/security/entry/cve-2021-44228

For product "Apache HTTP Server (httpd)" they show "Not affected".


Locked

Return to “Security in Joomla! 3.x”