Ask a Question

Is readyapi 3.10.1 affected by log4j security vulnerability issues?

SOLVED
kiwi23
Occasional Contributor

Is readyapi 3.10.1 affected by log4j security vulnerability issues?

Is readyapi 3.10.1 affected by log4j security vulnerability issues? If so are we getting any new updates. ?

3 REPLIES 3
JoostDG
Frequent Contributor

I also would like to have a quick answer on this from Smartbear. 

From what I can see, the 2.11.0 version is used, which is part of the impacted versions (source: https://www.randori.com/blog/cve-2021-44228/) . Upgrading to 2.15.0 would be recommended.

JoostDG_0-1639382566992.png

 

JoostDG_1-1639382675860.png

 

nmrao
Community Hero

 

The same link your reply has how to mitigate, please refer the excerpt. So, one can update the respective scripts (such as ready-api.sh / testrunner.sh ; .bat / .cmd files for windows platform; have backup of the same scripts before updating so that if something does not work, you can rollback the file changes) under READY_HOME/bin to add the following in the JAVA_OPTS.

nmrao_0-1639394555043.png

 



Regards,
Rao.
D0UG
Community Manager

SmartBear is aware of the recently disclosed security issue affecting the open-source Apache “Log4j2” utility (CVE-2021-44228). The Security team is actively working to mitigate our exposure and continue to provide enhanced monitoring of our platforms to safeguard information. Resources potentially affected by this vulnerability have been identified and our Information Technology and Information Security teams are working closely together to remediate any potential exposure in our platforms and environment.

 

Please check https://smartbear.com/security/cve-2021-44228/ for further updates.


-----------------------
Sr. Director, Web & Digital Experience @ SmartBear
cancel
Showing results for 
Search instead for 
Did you mean: