When AlexisHR became aware of the Log4Shell vulnerability (CVE-2021-44228), we began investigating our systems to determine whether there had been any impact to them.
As of December 15, 09:00 CET, the following is the status of our investigation:
System | Status | Link |
AlexisHR | Not affected |
|
Internal Monitoring/tracking systems | Not affected |
|
Internal logging system | Affected and patched |
|
MongoDB Atlas | Not affected (we do not use Atlas Search) | |
Intercom | Affected and patched | |
Auth0 | Under investigation by our service provider | |
Google Cloud | Not affected | |
Cloudflare | Affected and patched |
This vulnerability continues to be exploited in the wild; we encourage any customers who manage environments containing Log4j to update to the latest version as soon as possible.
We continue to monitor our system and services for any updates. If you have any questions, please contact [email protected]
