Log4J security incident
Like many others here, I guess your companies are very concerned with the management of the latest log4j vulnerability. CVE - CVE-2021-44228 (mitre.org)
Collibra is doing a great job of communicating updates on the trust center page: Status dashboard | Collibra
but some info is lacking:
- How come the Edge servers are not impacted while they use log4j 2.13.3?
- Is there a security risk on elasticsearch? (i.e. is it internat facing?)
arthurburkhardt
Posted 4 years ago · Edited 1 year ago·Last reply 4 years ago
5 comments
arthurburkhardt
OP4 years ago · EditedThanks, @heather.wheeland.collibra.com . I reached out to our CSM to learn more about the new vulnerability CVE-2021-45046, recently discovered on december 14th, impacting log4J 2.15
Alexandra Jorgenson
Admin4 years ago · Edited@arthur.burkhardt, just making sure you saw this comment re Edge in the dashboard, right?: “¹Collibra Edge includes log4j-*.jar libraries. However, the vulnerability is neutralized because log4j-core is not included. Please note that vulnerability scanning tools may report false positives as a result.”
arthurburkhardt
OP4 years ago · EditedThanks, @heather.wheeland.collibra.com . I reached out to our CSM to learn more about the new vulnerability CVE-2021-45046, recently discovered on december 14th, impacting log4J 2.15
arthurburkhardt
OP4 years ago · EditedYes, it was updated to reflect the latest changes.
I have to say I’m pretty impressed with the trust dashboard. It was great to be updated regularly on the situation at Collibra, and I understand given the urgency and quick updates that it was not possible to immediately reflect the latest information. Good job, Collibra security team!
heatherwheeland
·4 years ago · EditedArthur,
Thanks for sharing our Status Dashboard. As we learn more, we are actively updating the Status Dashboard, including regarding Edge. Please note that a status could change. All vulnerabilities reported in products and components on the Status Dashboard are of a security concern, and we are actively working to deploy and provide fixes accordingly.
Please reach out to your account representative for more information.