Security
Update Dec 28, 2021. We are aware of CVE-2021-44832 and are continuing to patch any systems that include log4j updated as patches become available.
Update Dec 20 2021: We are keeping any systems that include log4j updated as patches become available additional CVEs related to Log4j. This blog relates to the original Apache Log4j CVE-2021-44228. We are aware of CVE-2021-45105 and have applied all available mitigations and updates.
Dec 15 2021: This blog is an update to the previous blog about Concrete and the Log4j vulnerability posted Dec 13.
Update Dec 28, 2021. We are aware of CVE-2021-44832 and are continuing to patch any systems that include log4j updated as patches become available
Update Dec 20, 2021: We are keeping any systems that include log4j updated as patches become available for additional CVEs related to Log4j. This blog relates to the original Apache Log4j CVE-2021-44228. We posted a blog about follow on vulnerability CVE 2021-45046. We are aware of CVE-2021-45105 and have applied all available mitigations and updates. We are remaining vigilant.
On December 9, 2021 a serious vulnerability in the Java-based logging package Log4j was publicly disclosed. In broad strokes, this vulnerability (CVE-2021-44228) allows an attacker to execute code on a remote server, it’s a pretty big deal.
In the past several days, there have been a number of articles raising the alarm about content management systems which allow executable files to be uploaded by an administrator, who already has complete control over the website.
A vulnerability in concrete5 which permitted authenticated users to view the contents of arbitrary messages was reported on February 11, 2019. No information identifying individuals was exposed. A fix was added to the concrete5 repository on Monday, February 15, 2019 and mitigated on the concrete5.org website on Wednesday, February 20, 2019.
All concrete5 sites should update to versions 8.4.5 or 5.6.4.0. The concrete5.org website has been upgraded and messages are no longer vulnerable, and no evidence was found that suggests this vulnerability was exploited on the website.
The timeline and details around the reporting of a security issue with ProEvents...
- ← Previous
- 1
- 2
- 3
- 4 (current)
- Next →