Code: Select all
Brekeke PBX, Version 3.8.3.4, Pro
Code: Select all
OpenJDK 8u312-b07-1~deb9u1
Code: Select all
Debian Stretch
Code: Select all
/
Code: Select all
CVE-2021-44228
as you probably heared through the news there as new security regarding log4j (https://nvd.nist.gov/vuln/detail/CVE-2021-44228).
I've found the following files in the PBX directory:
Code: Select all
/webapps/pbx/WEB-INF/lib$
-rw-r--r-- 1 tomcat tomcat 127 Feb 2 2018 log4j-core.jar
-rw-r--r-- 1 tomcat tomcat 106494 Feb 2 2018 log4j.jar
How I can find out, which log4j version is used since extracting the log4j.jar file and having a look at the MANIFEST.MF located in the META-INF directory doesn't has much information in it...
And do you know if there's any fix already provided for this? At the moment the Brekeke news feed is empty regarding this.
Looking forward to hear from you.
Best regards
Code: Select all