Juniper R2 2021 - Log4j vulnerability verification and correction

Description

The 'formatMsgNoLookups' property was added in version 2.10.0, per the JIRA Issue LOG4J2-2109 that proposed it. Therefore the 'formatMsgNoLookups=true' mitigation strategy is available in version 2.10.0 and higher, but is no longer necessary with version 2.16.0, because it then becomes the default behavior .

Environment

None

Potential Workaround

None

Checklist

hide

TestRail: Results

Activity

Show:

Tino R. December 15, 2021 at 6:20 PM

R3 and R2 had the same version of mod-erm-usage-harvester (3.1.2).
A release for R3 (3.1.3) is available and should be used for R2 as well.

Done

Details

Assignee

Reporter

Priority

Development Team

Leipzig

Fix versions

Release

R2 2021 Hot Fix #5

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs
Created December 15, 2021 at 11:16 AM
Updated January 25, 2022 at 1:33 AM
Resolved December 15, 2021 at 6:19 PM
TestRail: Cases
TestRail: Runs