A customer asked if the vulnerable Apache Log4j library is used by Salesforce and if so, what can they do to limit the vulnerability?
A quick searched found a reference to the Log4j library in the documentation for DataLoader log file. (https://developer.salesforce.com/docs/atlas.en-us.dataLoader.meta/dataLoader/loader_logging.htm )
Anybody have anything to contribute on this topic? (https://www.zdnet.com/article/security-warning-new-zero-day-in-the-log4j-java-library-is-already-being-exploited/ ) Thanks in advance!
29 réponses
There is now a status page for the vulnerability review - Apache Log4j2 vulnerability (salesforce.com)