- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Square Online and Apache Security Vulnerabilities
Hi - does Square Online/Weebly/etc. make use of Apache's Log4j Java-based logging... or Apache Struts2, Apache Solr, Apache Druid, Apache Flink, etc.?
Apache is pervasive in the web hosting world, so I would not be surprised if it does.
I trust you've seen reports in the news regarding a serious and easy-to-exploit security flaw in these Apache products, e.g. https://logging.apache.org/log4j/2.x/security.html
What is Square's position? Not applicable, or patches being deployed?
cc: @tranguyen
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report Inappropriate Content
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Hi @allan21, thank you for sharing this.
I've shared this with the appropriate team and will follow up once I have an update from them.
Community Engagement Program Manager, Square
Have a burning question to ask in our Question of the Week? Share it with us!
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report Inappropriate Content
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Thanks @tranguyen - I forgot to mention it also affects older versions of Logstash, which lots of systems use.
Even the British and American governments have put out warnings about this flaw:
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report Inappropriate Content
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Update please? If it’s not an issue, great. If it is, please reassure us.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report Inappropriate Content