LOG4J Vulnerability

Re: LOG4J Vulnerability

by Anthony Borrow -
Number of replies: 0
Picture of Core developers Picture of Plugin developers Picture of Testers
Thanks Michael, as you noted, things to watch out for in plugins are Java and jar files. When I did a search on my system, I came up with an old plugin that made use of Red5 back in the day when it was using log4j (which is over 10 years ago). At one point, back in the CVS days, I liked the idea of being able to search all of the plugins for particular vulnerabilities. This would require a bit of scripting but I think the community could probably identify the plugins that might potentially be impacted and flag them. Again, just to be clear, Red5 reports that the current version is not affected by the log4j vulnerability.  If folks have any questions about a particular plugin, it never hurts to ask. I would be interested in seeing a list of plugins that would require Java to be installed on a server and then go through that list and ensure that they are unaffected. Peace - Anthony