Using Sonarqube 9.2.4, which has log4j 2.17.0 and it's vulnerable to CVE-2021-44832 in below link

Hi @kshitizsh12,

Welcome to the community!

As previously stated, our security researchers have found no way to exploit even the original vulnerability in SonarQube. The patches we released were issued “from an abundance of caution” and “to eliminate confusion and avoid false-positive[s] from vulnerability scanning tools”.

The CVE you reference requires “a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server”. Since SonarQube’s only use of Log4J is via Elasticsearch, I think you can rest easy that those conditions don’t exist.

In short, we do not plan to release patches to address this CVE.

 
HTH,
Ann

1 Like