CVE-2021-44228

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
jabi27
Posts: 34
Joined: Thu Jan 19, 2017 4:30 pm

CVE-2021-44228

Post by jabi27 »

Hi
Is Nagios and/or the ELK stack affected by CVE-2021-44228 ?

Best

Jan
CBoekhuis
Posts: 212
Joined: Tue Aug 16, 2011 4:55 am

Re: CVE-2021-44228

Post by CBoekhuis »

I also would like a reply on this matter, a swift reply from Nagios would be appreciated.

Grtz. Hans
mka
Posts: 3
Joined: Wed Sep 12, 2012 9:10 am

Re: CVE-2021-44228

Post by mka »

I am also interested here, if XI is affected by this vulnerability.
mka
Posts: 3
Joined: Wed Sep 12, 2012 9:10 am

Re: CVE-2021-44228

Post by mka »

I would also like to know, if Nagios XI is affected.
vconnected
Posts: 7
Joined: Tue May 19, 2015 8:18 am

Re: CVE-2021-44228

Post by vconnected »

Me too!

Code: Select all

[root@nagiosls /]# find / -name *log4j*

/usr/local/nagioslogserver/elasticsearch/lib/apache-log4j-extras-1.2.17.jar
/usr/local/nagioslogserver/elasticsearch/lib/log4j-1.2.17.jar
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/jruby-jms-1.2.0-java/test/log4j.properties
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch_java-2.1.3/vendor/jar-dependencies/runtime-jars/apache-log4j-extras-1.2.17.jar
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch_java-2.1.3/vendor/jar-dependencies/runtime-jars/log4j-1.2.17.jar
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-beats-3.1.14-java/vendor/jar-dependencies/log4j
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-beats-3.1.14-java/vendor/jar-dependencies/log4j/log4j
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-beats-3.1.14-java/vendor/jar-dependencies/log4j/log4j/1.2.17/log4j-1.2.17.jar
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/zk-1.9.6/spec/log4j.properties
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-log4j-2.0.7-java
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-log4j-2.0.7-java/logstash-input-log4j.gemspec
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-log4j-2.0.7-java/vendor/jar-dependencies/runtime-jars/log4j-1.2.17.jar
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-log4j-2.0.7-java/lib/logstash/inputs/log4j.rb
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-log4j-2.0.7-java/lib/logstash-input-log4j_jars.rb
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/jruby-kafka-1.5.0-java/lib/org/slf4j/slf4j-log4j12
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/jruby-kafka-1.5.0-java/lib/org/slf4j/slf4j-log4j12/1.7.13/slf4j-log4j12-1.7.13.jar
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/jruby-kafka-1.5.0-java/lib/log4j
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/jruby-kafka-1.5.0-java/lib/log4j/log4j
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/jruby-kafka-1.5.0-java/lib/log4j/log4j/1.2.17/log4j-1.2.17.jar
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/zookeeper-1.4.11-java/spec/log4j.properties
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/slyphon-log4j-1.2.15
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/slyphon-log4j-1.2.15/log4j.gemspec
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/slyphon-log4j-1.2.15/lib/log4j-1.2.15.jar
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/slyphon-log4j-1.2.15/lib/log4j.rb
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/slyphon-log4j-1.2.15/lib/log4j
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/specifications/slyphon-log4j-1.2.15.gemspec
/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/specifications/logstash-input-log4j-2.0.7-java.gemspec
smlushing
Posts: 11
Joined: Thu Oct 26, 2017 8:18 am

Re: CVE-2021-44228

Post by smlushing »

I would like to know ASAP also
danniiffxi
Posts: 121
Joined: Tue Jan 30, 2018 3:29 am
Location: UK

Re: CVE-2021-44228

Post by danniiffxi »

I would also like to know.

From what I can see log4j is not used on Nagios XI, but is on Nagios Log.
DoIT-Systems
Posts: 2
Joined: Tue May 07, 2019 10:35 am

Re: CVE-2021-44228

Post by DoIT-Systems »

add another concerned customer to the list of would like to know...
prashanthan1987
Posts: 5
Joined: Thu Jul 26, 2018 4:33 am

Re: CVE-2021-44228

Post by prashanthan1987 »

Anyone from Nagios support to share the updates quickly on this subject matter
pnnagios
Posts: 47
Joined: Wed Dec 14, 2011 9:48 am

Re: CVE-2021-44228

Post by pnnagios »

Another customer using Nagios XI, that would like to know if we are affected by this vulnerability.
Thank you.
Locked