Apache Log4j vulnerability CVE-2021-44228

10 Comments

  • Evan Tribley

    Would be great to get some kind of response on this. I am surprised they did not mention anything proactively.

    0
  • Mark McLane

    I sent an inquiry to serviceincident@zendesk.com about this, maybe a few more tickets raised to the same address will nudge them into a reply...

    2
  • Evan Tribley

    Great idea, will do!

    0
  • Mark McLane

    I got a response from Zendesk support stating the following:

    Zendesk does use Log4j in some parts of our infrastructure. We have identified the appropriate mitigations and updates, and are implementing these in our environment.

    Zendesk and the industry are continuing investigations into this Apache security event. At this point in time, we are not aware of any impact to your account. We will keep you informed should this assessment change.

    1
  • Mark McLane

    Check out ZD's new advisory regarding this: https://support.zendesk.com/hc/en-us/articles/4413583476122

    2
  • FintechOs SRL

    Cool, thanks Mark McLane for the detailed updates!

    Happy EOY, good people! :) 

    0
  • Eric Nelson
    Zendesk Developer Advocacy
    Hey Everyone,

    First off - thanks for dropping the link to our advisory Mark!

    Please let me know if you have any further questions around this vulnerability or our remediation steps.

    Thanks! 
    0
  • Mike

    Eric Nelson

    Will Zendesk inform when all necessary fixes are deployed?

    This allows your customers (us) to report this internally as done.

    0
  • Eric Nelson
    Zendesk Developer Advocacy

    Hey Mike

    We've put out some comms here that discuss what we've done to remediate this so far and our steps to continue to monitor it.

    1
  • Mick O'Donnell
    Zendesk Product Manager

    Hello,

    I just wanted to add one additional piece of information to this conversation. Zendesk does not use Log4j in our mobile SDKs, so there is no impact on that side of the Zendesk platform. 

    1

Please sign in to leave a comment.

Powered by Zendesk