{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_informational_advisory","csaf_version":"2.1","title":"Log4j2 Remote Code Execution Vulnerability aka Log4Shell (CVE-2021-44228)","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2021-00003","status":"final","version":"33","initial_release_date":"2021-12-09T10:00:00+00:00","current_release_date":"2026-07-28T01:13:10.729509+00:00","revision_history":[{"date":"2021-12-09T10:00:00+00:00","number":"33","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2021-00003"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2021-44228"}],"notes":[{"category":"summary","text":"#### Update 1 – \n\nAfter review, no WatchGuard products or services are vulnerable to the recently upgraded vulnerability CVE-2021-45046. This vulnerability requires a non-default configuration that no WatchGuard product or service has in use. Regardless, we have updated our services out of an abundance of caution.\n\n#### Update 2 – \n\nResearchers recently discovered and disclosed CVE-2021-4104, a remote code execution vulnerability in the older Log4j 1.2 release. This vulnerability requires a non-default configuration with the JMSAppender module enabled. While WatchGuard System Manager uses a vulnerable version of Log4j 1.2, it does not use the JMSAppender module and is not vulnerable to this exploit. WatchGuard does not use Log4j 1.2 in any other product or service.\n\nOn 9 December 2021, researchers disclosed a critical, unauthenticated remote code execution (RCE) vulnerability in log4j2, a popular and widely-used logging library for Java applications. An attacker could exploit this vulnerability to run untrusted code on vulnerable systems.\n\nThere are several mitigating factors, including the version of Java the application uses with JDK versions newer than 6u11, 7u201, 8u191 and 11.0.1 not affected by the common and trivial LDAP attack vector. Additionally, log4j2 implementations that have explicitly disabled JNDI lookups are not vulnerable.\n\nNo WatchGuard products or services are affected by this vulnerability","title":"Summary"}]}}