Java Zero Day Question

I think we’re crafting some kind of official statement, but there’s nothing to worry about.

Ignition doesn’t use log4j as its logging backend. Both 7.9 and 8.x versions use a different backend called logback instead. Even old unsupported versions of Ignition that did use log4j used version 1.x, which isn’t affected.

For anyone interested this is the CVE: CVE - CVE-2021-44228

8 Likes