CVE-2021-44228 / log4j 0-day vulnerability

CVE-2021-44228 / log4j 0-day vulnerability

by Jennifer Volk -
Number of replies: 7

Hi Moodle peeps,

I haven't seen anything yet about Moodle's status on this Java vulnerability - can you please let us know what your level of vulnerability/patching is for this?

https://www.lunasec.io/docs/blog/log4j-zero-day/

Thanks



Average of ratings: -
In reply to Jennifer Volk

Re: CVE-2021-44228 / log4j 0-day vulnerability

by Marcus Green -
Picture of Core developers Picture of Particularly helpful Moodlers Picture of Plugin developers Picture of Testers
" can you please let us know what your level of vulnerability"
Does Moodle use or depend on java or log4j?
In reply to Marcus Green

Re: CVE-2021-44228 / log4j 0-day vulnerability

by Dave Perry -
Picture of Testers
I've been looking at this this morning as our security analyst in IT flagged it. Apache (the web server we run) doesn't use it, but log4j is an Apache project which is probably where some people are getting concerned without looking at it.
So unless you're running it in a Java servlet container (which for PHP would be very odd), the answer should be no.
Average of ratings: Useful (3)
In reply to Jennifer Volk

Re: CVE-2021-44228 / log4j 0-day vulnerability

by Andrew Lyons -
Picture of Core developers Picture of Moodle HQ Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers Picture of Testers
Absolutely zero. Why do you think it would be an issue for Moodle?

Moodle is a PHP project and does not use Java at all (at least, not in the core product - I can’t speak for third-party plugins). We don’t use Log4J or any of the log4j framework or formats at all.
Average of ratings: Useful (5)
In reply to Andrew Lyons

Re: CVE-2021-44228 / log4j 0-day vulnerability

by Dave Perry -
Picture of Testers
Bear in mind that some people are having IT managers who haven't looked at it properly just panic, and these managers are asking their staff to look at it.
Ours I'm told was worried, just by the mention of the word Apache - I looked at the link his security analyst sent me, and realised that as it was an Apache project that's where the concern/confusion arose.
In reply to Andrew Lyons

Re: CVE-2021-44228 / log4j 0-day vulnerability

by Kieran Jones -
Looks like it was historically used within Moodle once upon a time: https://docs.moodle.org/19/en/Emeeting_module_Log4j

I don't think there is anything wrong with pro-actively asking considering the associated risk. I found this thread as I was also looking.
In reply to Kieran Jones

Re: CVE-2021-44228 / log4j 0-day vulnerability

by Tim Hunt -
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers
Emeeting was never part of Moodle. It was (once upon a time) an add-on.