# Is SavaPage affected by the log4j shell vulnerability?

**URL:** https://community.savapage.org/t/is-savapage-affected-by-the-log4j-shell-vulnerability/190
**Category:** Deployment
**Tags:** log4jshell
**Created:** [December 21, 2021, 9:51am UTC](https://community.savapage.org/t/is-savapage-affected-by-the-log4j-shell-vulnerability/190 "2021-12-21T09:51:53Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![rijkr](https://community.savapage.org/user_avatar/community.savapage.org/rijkr/32/3_2.png) [@rijkr](https://community.savapage.org/u/rijkr)
#### Post date: [December 21, 2021, 9:51am UTC](https://community.savapage.org/t/is-savapage-affected-by-the-log4j-shell-vulnerability/190/1 "2021-12-21T09:51:53Z")

</div>

Short answer: no. SavaPage uses an older log4j 1.2.17 version. This version does support JNDI options in its JMS (Java Message Service) appender, but this appender is not used by SavaPage.

---

<div class="post-metadata">

### Author: ![Neustradamus](https://community.savapage.org/letter_avatar_proxy/v4/letter/n/6bbea6/32.png) [@Neustradamus](https://community.savapage.org/u/Neustradamus)
#### Post date: [December 31, 2021, 8:27am UTC](https://community.savapage.org/t/is-savapage-affected-by-the-log4j-shell-vulnerability/190/2 "2021-12-31T08:27:00Z")

</div>

But there are a lot of log4j CVEs!

- cve.ics-csirt io/cve?vendor=apache&product=log4j
- cve.mitre org/cgi-bin/cvekey.cgi?keyword=Apache%20Log4J

Another one in few days, to fix nvd.nist gov/vuln/detail/CVE-2021-44832:

- logging.apache org/log4j/2.x/security.html

Only recent CVEs:

- CVE-2021-4104
- CVE-2021-44228
- CVE-2021-44832
- CVE-2021-45046
- CVE-2021-45105

Note that there is a logback CVE too:

- CVE-2021-42550

And previously slf4j etc.

---

<div class="post-metadata">

### Author: ![rijkr](https://community.savapage.org/user_avatar/community.savapage.org/rijkr/32/3_2.png) [@rijkr](https://community.savapage.org/u/rijkr)
#### Post date: [December 31, 2021, 10:46am UTC](https://community.savapage.org/t/is-savapage-affected-by-the-log4j-shell-vulnerability/190/3 "2021-12-31T10:46:04Z")

</div>

@Neustradamus Yes, there are a many log4j 2.x CVEs. Could you be more specific about log4j **1.2.17** vulnerabilities that might affect SavaPage?
