Page 1 of 1

Does TSPLUS use the log4j vulnerability directory (Exploit CVE-2021-44228)?

Posted: Sun Dec 12, 2021 10:53 pm
by clickone
Does TSPLUS use the log4j vulnerability directory (Exploit CVE-2021-44228)?

Hello,
On 9/12/2021 a new exploit was announced in the log4j library, named CVE-2021-44228
Details about the vulnerability can be seen here
https://cve.mitre.org/cgi-bin/cvename.c ... 2021-44228

TSPLUS is written in Java.
I wanted to know if there is a log4j library used, and if so, what should I do to beware of this exploit?

Thanks!

Re: Does TSPLUS use the log4j vulnerability directory (Exploit CVE-2021-44228)?

Posted: Wed Dec 15, 2021 10:28 pm
by rwegner
Bumping cause I would like to know this as well!

Re: Does TSPLUS use the log4j vulnerability directory (Exploit CVE-2021-44228)?

Posted: Fri Dec 17, 2021 11:02 pm
by juwagn
clickone wrote:
Sun Dec 12, 2021 10:53 pm
TSPLUS is written in Java.
Hello,

html5 library (html5-rdp/webserver)written in Java doesn't use log4j.

Sincerely yours, JW.