kewakl (Customer) asked a question.

Techsupport request: PAC/P1-AM (Arduino) log4j vulnerability advice

I do not mean to sound alarmist, just looking for knowledgeable input and advice.

 

Anyone who had access to tech news last week and over the weekend should have seen the headlines re: log4j/log4shell

 

I have looked in the downloaded files and in the installation folders for PAC Suite and find no references to log4j.

Digging deeper, I do find log4j entries in:

C:\Program Files (x86)\AutomationDirect\Productivity Suite 1.7.1.1\lib\commons-logging.jar\org\apache\commons\logging\impl\

C:\Program Files (x86)\AutomationDirect\Productivity Suite 3.10.2.1\lib\commons-logging.jar\org\apache\commons\logging\impl\

 

(Log4jCategoryLog.class, Log4jFactory.class, Log4JLogger.class)

 

I do find multiple occurrences of log4j (2.12.0) in my arduino install folder.

 

(zdnet 2021/12/10 Systems and services that use the Java logging library, Apache Log4j between versions 2.0 and 2.14.1 are all affected, including many services and applications written in Java.)

 

 

Please advise. Can log4j/log4shell impact our project development, maintenance ....

 


  • ADC_AutomationControls_PM01 (AutomationDirect)

    Regarding Productivity CPUs and Productivity Suite, the Log4j library is not used in any part of Productivity. Class names that are found in the commons-logging.jar file are references but are unused and their targets are unpopulated. We are exploring an updated release of Productivity Suite that has these references removed, but at this time there appears to be no risk from this library in Productivity Suite or Productivity CPUs.

    Selected as Best