Sonarcloud and log4j vulnerability

Given the log4j vulnerability and recommended configuration changes suggested here: SonarQube and the Log4J vulnerability

Can someone from SonarCloud confirm that these changes have been applied?

Thanks,
Luke.

3 Likes

Hey there.

Thanks for asking. Our investigation leads us to believe SonarCloud is not vulnerable in its current state.

In any case, we take such reports seriously and we will update log4j on Monday to be extra sure.

@Colin,

Wanted to check in to see if your team has updated log4j.

Thanks,
Max

Hey @Max_Kroll

We have updated it – and it was deployed.

1 Like

Hi @Colin,

That was quick! Thanks so much for the confirmation.

Max

We’ll handle any further updates on this thread.

https://community.sonarsource.com/t/sonarqube-sonarcloud-and-the-log4j-vulnerability/54721/25

So I’ll close this one.