menu

Feed available - Subscribe to our feed to stay up to date on upcoming maintenance and incidents.

CVE-2021-44228 Discovered

Incident window: December 10, 2021
The cloud operations and security team have thoroughly investigated the reported Log4j vulnerability (CVE-2021-44228) and found no current vulnerability to the services hosted on the VoltMX Cloud due to the newer versions of JVMs currently in use.
There is an additional attack vector reported against the log4j vulnerability and the teams are looking to see if this applies to VoltMX Cloud. This variation claims to work around the JVM protections.

Impacted Cloud services:

Impact Level : high

There is no impact to customer’s runtime environment at this time. As always, we would encourage customers to use caution when uploading custom Java code to their environments.

[2021-12-13 11:54 UTC] There is an additional attack vector reported against the log4j vulnerability and the teams are looking to see if this applies to VoltMX Cloud.

[2021-12-13 11:54 UTC] The is a risk from the latest log4j attack vector and we are patching the affected products and will be updating clusters in the coming hours.

[2021-12-14 08:14 UTC] Resolved. All VoltMX environments are fully patched for CVE-2021-44228.