PSA: Potential security vulnerability in Elasticsearch and more via Apache Log4j (Log4Shell)

PixelGoose

Administrator
Staff member
It has come to our attention today that a vulnerability has been discovered in popular Java logging library Log4j 2 which may allow attackers to arbitrarily execute code (remote code execution).

Apache Log4j 2 is bundled with and used in many Java applications including Elasticsearch.

XenForo itself is not directly exploitable, and we are currently investigating whether XenForo Enhanced Search can be used as a vector at all, but this is potentially significant enough that an abundance of...

Read more

Continue reading...
 

About us

PixelGoose Studio is glad to offer you a variety of premium XenForo themes. All our themes are beautiful and unique. We are constantly working to improve our themes and give them new features and options.

If you have any questionas or suggestions, feel free to contact us!

Buy the theme

Metro Theme for Xenforo
Where to purchase?
Top Bottom