# Log4j Vulnerability Confirmation

**URL:** https://discourse.openondemand.org/t/log4j-vulnerability-confirmation/1842
**Category:** Get Help
**Tags:** question
**Created:** [December 14, 2021, 7:46pm UTC](https://discourse.openondemand.org/t/log4j-vulnerability-confirmation/1842 "2021-12-14T19:46:15Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![DelilahYM](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/delilahym/32/797_2.png) [@DelilahYM](https://discourse.openondemand.org/u/DelilahYM)
#### Post date: [December 14, 2021, 7:46pm UTC](https://discourse.openondemand.org/t/log4j-vulnerability-confirmation/1842/1 "2021-12-14T19:46:15Z")

</div>

Hi All,

Tufts University became aware of the **log4j vulnerability** ([CVE-2021-44228](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228)) and is actively investigating and evaluating the potential impact as well as the actions need to be taken to protect against this vulnerability.  
Can anyone confirm if Open OnDemand is affected (any version)? And/or any other software/services your site uses are affected so we can be aware of it as well?  
Thank you!  
Best,  
Delilah Maloney

---

<div class="post-metadata">

### Author: ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)
#### Post date: [December 14, 2021, 8:43pm UTC](https://discourse.openondemand.org/t/log4j-vulnerability-confirmation/1842/2 "2021-12-14T20:43:44Z")

</div>

No version of OnDemand itself is affected. We don’t use any Java library directly.

TYSM about asking for Apps, because I thanked my lucky stars we don’t use Java and forgot all about it.

Apps could be affected, but the attack vector here is small. Matlab comes to mind, as it uses Java - though they say they’re not affected. Though we have old versions (back to 2015a) that may be.

[https://www.mathworks.com/matlabcentral/answers/1610640-apache-log4j-vulnerability-cve-2021-44228-how-does-it-affect-matlab-run-time](https://www.mathworks.com/matlabcentral/answers/1610640-apache-log4j-vulnerability-cve-2021-44228-how-does-it-affect-matlab-run-time)

I just did a spot check on 2015B and 2020A and they both use version 1.2.

I cannot think off of the top of my head what other common apps but I’ll let this topic know if I find any.

It’s also worth stating the attack vector here is to inject something through your app that’s listening on a port.

Now folks can’t send things to your MATLAB instance for example (it’s not exposed any ports), but they could share a `.m` file that does the trick. But even then, If you accept a vulnerable matlab file - There are easier ways to achieve the same result, like using the `system()` function directly.

---

<div class="post-metadata">

### Author: ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)
#### Post date: [December 14, 2021, 8:44pm UTC](https://discourse.openondemand.org/t/log4j-vulnerability-confirmation/1842/3 "2021-12-14T20:44:39Z")

</div>

Which is a long winded way to say - No OnDemand version is affected, but it’s worth a spot check on the apps to see if they expose any ports.

---

<div class="post-metadata">

### Author: ![DelilahYM](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/delilahym/32/797_2.png) [@DelilahYM](https://discourse.openondemand.org/u/DelilahYM)
#### Post date: [December 14, 2021, 9:34pm UTC](https://discourse.openondemand.org/t/log4j-vulnerability-confirmation/1842/4 "2021-12-14T21:34:56Z")

</div>

Thank you so much Jeff! This is reassuring.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/b/bae70bd0ed39a3ae769c2108155f4cb3e9da8385.png) [@system](https://discourse.openondemand.org/u/system)
#### Post date: [June 12, 2022, 9:35pm UTC](https://discourse.openondemand.org/t/log4j-vulnerability-confirmation/1842/5 "2022-06-12T21:35:00Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
