Log4Shell log4j vulnerability (CVE-2021-44228) doe...
# sdf
s
Log4Shell log4j vulnerability (CVE-2021-44228) does this affect sdf / netsuite /Oracle etc
b
taking a look through cli-2021.2.2.jar
the answer appears to be yes
they appear to have log4j 2.14.1 in their maven dependencies
s
Is there a solution ? Or wait till they catch on
l
Hi, We are working right now to upgrade log4j dependency to 2.16.0 version, which fixes this vulnerability. We would release a new version in the upcoming days and keep you updated.
s
@Luis Pérez Villegas (NS Devtools SE) will we see an official announcement or update anywhere (SuiteAnswers, etc)?
l
@Sam. Yes sure, I don't know if it would be in SuiteAnswers but in all the places where it is normally announced. Also, we would announce it in this channel.