Skip to main content

Log4Shell Vulnerability (CVE-2021-44228) and AlexisHR

Regarding the Log4j Vulnerability

T
Written by Tobias Carneteg

When AlexisHR became aware of the Log4Shell vulnerability (CVE-2021-44228), we began investigating our systems to determine whether there had been any impact to them.

As of December 15, 09:00 CET, the following is the status of our investigation:

System

Status

Link

AlexisHR

Not affected

Internal Monitoring/tracking systems

Not affected

Internal logging system

Affected and patched

MongoDB Atlas

Not affected (we do not use Atlas Search)

Intercom

Affected and patched

Auth0

Under investigation by our service provider

Google Cloud

Not affected

Cloudflare

Affected and patched

This vulnerability continues to be exploited in the wild; we encourage any customers who manage environments containing Log4j to update to the latest version as soon as possible.

We continue to monitor our system and services for any updates. If you have any questions, please contact [email protected]

Did this answer your question?