# CVE-2021-44228 - log4j - Discourse פגיע?

**URL:** https://meta.discourse.org/t/cve-2021-44228-log4j-discourse-vulnerable/211824
**Category:** Self-hosting
**Created:** [11 בדצמבר,‏ 2021,‏ 1:18pm UTC](https://meta.discourse.org/t/cve-2021-44228-log4j-discourse-vulnerable/211824 "2021-12-11T13:18:05Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![a.harper](https://avatars.discourse-cdn.com/v4/letter/a/e68b1a/32.png) [@a.harper](https://meta.discourse.org/u/a.harper)
#### Post date: [11 בדצמבר,‏ 2021,‏ 1:18pm UTC](https://meta.discourse.org/t/cve-2021-44228-log4j-discourse-vulnerable/211824/1 "2021-12-11T13:18:05Z")

</div>

Hi all

Is the vulnerable log4j library in use by Discourse - can an employee please issue a statement on potential exposure/review.

Thanks

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [11 בדצמבר,‏ 2021,‏ 2:26pm UTC](https://meta.discourse.org/t/cve-2021-44228-log4j-discourse-vulnerable/211824/2 "2021-12-11T14:26:35Z")

</div>

Log4J is a Java library. Discourse is written in Ruby, not Java.

---

<div class="post-metadata">

### Author: ![a.harper](https://avatars.discourse-cdn.com/v4/letter/a/e68b1a/32.png) [@a.harper](https://meta.discourse.org/u/a.harper)
#### Post date: [11 בדצמבר,‏ 2021,‏ 3:08pm UTC](https://meta.discourse.org/t/cve-2021-44228-log4j-discourse-vulnerable/211824/3 "2021-12-11T15:08:26Z")

</div>

Thanks, so from the hosting side of things there is no Apache and log4j there?

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [11 בדצמבר,‏ 2021,‏ 3:26pm UTC](https://meta.discourse.org/t/cve-2021-44228-log4j-discourse-vulnerable/211824/4 "2021-12-11T15:26:03Z")

</div>

Correct, a standard installation of Discourse doesn’t use Apache.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [11 בדצמבר,‏ 2021,‏ 5:07pm UTC](https://meta.discourse.org/t/cve-2021-44228-log4j-discourse-vulnerable/211824/5 "2021-12-11T17:07:48Z")

</div>

Note that any self-hosted or non-standard Discourse installs running on Apache httpd are not affected either.

The Apache HTTP server project does not use the Apache Log4J library, they are both projects from the Apache foundation so they share a name, but that’s about it.

---

<div class="post-metadata">

### Author: ![VirgilVulpes](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/virgilvulpes/32/201890_2.png) [@VirgilVulpes](https://meta.discourse.org/u/VirgilVulpes)
#### Post date: [16 בדצמבר,‏ 2021,‏ 9:50pm UTC](https://meta.discourse.org/t/cve-2021-44228-log4j-discourse-vulnerable/211824/6 "2021-12-16T21:50:14Z")

</div>

Should those of us who run Discourse instances with java-based plugins disable said plugins?  
(I’m definitely not a software engineer. That’s all Greek to me)

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [16 בדצמבר,‏ 2021,‏ 9:52pm UTC](https://meta.discourse.org/t/cve-2021-44228-log4j-discourse-vulnerable/211824/7 "2021-12-16T21:52:45Z")

</div>

Discourse Plugins are written in Ruby (on Rails) and Javascript (with Ember), so I’m not sure which plugins you are referring too?

NB Javascript and Java are not the same thing.

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [20 בדצמבר,‏ 2021,‏ 9:28am UTC](https://meta.discourse.org/t/cve-2021-44228-log4j-discourse-vulnerable/211824/8 "2021-12-20T09:28:02Z")

</div>

> [@Discourse and the Log4j vulnerability](https://meta.discourse.org/t/discourse-and-the-log4j-vulnerability/212609):
>
> On 9th December, [CVE 2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) was published for log4j, a commonly-used Java logging library. Subsequently, [CVE-2021-45046](https://nvd.nist.gov/vuln/detail/CVE-2021-45046) and [CVE-2021-45105](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105) have also been published. We’ve received a number of questions about these vulnerabilities, and whether they affect Discourse. Discourse is a Ruby application, and therefore does not make any use of this Java library. In addition, our [standard installation instructions](https://github.com/discourse/discourse/blob/main/docs/INSTALL-cloud.md) for self-hosted installations do not include any Java components. Managed [discourse.o…](http://discourse.org)

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [20 בדצמבר,‏ 2021,‏ 9:28am UTC](https://meta.discourse.org/t/cve-2021-44228-log4j-discourse-vulnerable/211824/9 "2021-12-20T09:28:13Z")

</div>


