SlideShare a Scribd company logo
1 of 7
Download to read offline
Privacy - Terms
cPanel Plugin Contains Log4j Vulnerability
Recently, one of the most popular control panels named cPanel released a
patch to correct a flaw in the log4j Java library. However, the vulnerability is
known as Log4Shell and is also described as a catastrophic vulnerability by
researchers.
Does Log4j (CVE-2021-44228) affect cPanel?
Yes, you have to uninstall the cPanel solr plugin because it is vulnerable.
However, an update in version 8.8.2-4+ has been announced to mitigate CVE-
2021-44228 to the Cpanel-devecot-solr RPM.
“We strongly advise all WordPress site customers running WordPress sites with
IMAP messaging protocol to confirm they are running the latest version which
patches this vulnerability.”
Log4j Critical Log4Shell Vulnerability


0
0

 
 

0
0
3 min read
cPanel Plugin Contains Log4j
Vulnerability
💬 Chat with us
Log4j is a Java library that is used for email and found in the basic cPanel plugin
called cPanel Dovecot Solr plugin. It adds a drop-in functionality to many online
software products. Keep in mind that it is not something that anyone would
generally download and use. This plugin is a must-have component of the IMAP
messaging protocol.
The log4j vulnerability is the most dangerous one, which is rated at 10 on a
scale of 1 to 10, where 1 is the minimum level, and 10 is the maximum.
cPanel describes it as:
cPanel Web Host Control Panel
cPanel is the most widely used and easy-to-use web hosting control panel that
allows business owner or developers to easily manage their website hosting
environment.

“The cPanel Solr plugin enables Internet
Message Access Protocol (IMAP) full-text
search (FTS) indexing (powered by Apache Solr
™), which provides fast search capabilities for
IMAP mailboxes.”
cPanel offers a graphical user interface (GUI) like windows over dos OS, and it is
also similar to a desktop interface. If you are a non-tech person, you can also
perform tasks like PHP version update, checking firewalls, and adding SSL
certificates, among others.
According to research conducted by BuiltWith, more than 3 million users have
installed cPanel to manage their hosting.
United States Government Statement on Log4Shell Vulnerability
The US Government Cybersecurity and Infrastructure Security Agency (CISA)
published a statement on November 11, 2021, urging software developers and
vendors that patch/update the log4j library in their products and for the vendors
to inform their customers.
The Director of CISA, Jen Easterly, wrote:
Usually, end users totally rely on their software vendors, and it is compulsory for
the vendors to update their community and take possible steps such as
identifying, mitigating, and patching their products.

“CISA is working closely with our public and
private sector partners to proactively address a
critical vulnerability affecting products
containing the log4j software library.”
The statement says that the Joint Cyber Defense Collaborative, National
Security Agency, and the FBI are also coordinatively working towards creating
awareness and its mitigation process proactively.
This statement includes:
Mitigation Process for CVE-2021-44228
It was officially announced on the cPanel discussion forum that cPanel
contained the log4j library, and it can be a security risk. However, you can check
if this RPM is installed by executing the following command:
RPM-based versions
Ubuntu-based versions
Example – if installed:
For more detailed information: Visit our recent announcement about Log4j
Vulnerability for more details.

“We continue to urge all organizations to review the latest CISA current
activity alert and upgrade to log4j version 2.15.0 or apply their appropriate
vendor recommended mitigations immediately.
To be clear, this vulnerability poses a severe risk. We will only minimize
potential impacts through collaborative efforts between the government
and the private sector. We urge all organizations to join us in this essential
effort and take action.”
1 # rpm -q cpanel-dovecot-solr --changelog | grep CVE-2021-44228
1 # zgrep -E CVE-2021-44228 /usr/share/doc/cpanel-dovecot-solr/changelog.Debian.gz
1 # rpm -q cpanel-dovecot-solr
1 cpanel-dovecot-solr-8.8.2-4.11.1.cpanel.noarch
Please try to patch it ASAP and share your valuable feedback with us, and we
would love to answer your questions in the comment section below.
Show Comments


0
0

 
 

0
0
 
Get started
Services
Want to Start Hosting on the Cloud or Looking for the Managed
Dedicated Servers ? You are on the right Place .....
+1
Managed Dedicated Servers
Managed DigitalOcean Cloud
Managed Magento Cloud
Managed Amazon Cloud (AWS)
Managed PHP Cloud
Managed Laravel Cloud
Managed Drupal Cloud
Managed Joomla Cloud
Managed Prestashop Cloud
Managed WooCommerce Cloud
Managed WordPress Cloud
Linux Shared Hosting
Windows Shared Hosting
Linux Reseller Hosting
Linux SEO Hosting
Domains
Linux Virtual Private Server (VPS)
Windows Virtual Private Server (VPS)
SEO RDP/VPS
Proxies
VPN
SSL
••
••
••
••
••
••
••
••
••
••
••
••
••
••
••
••
••
••
••
••
••
••
Company
About Us
Contact Us
Privacy Policy
Terms & Conditions
Service Level Agreement
DMCA
Acceptable Use Policy
Blog
Affiliates
Subscribe
Newsletter
Sign up for special offers:
Copyright TEMOK 2021.
All Rights Reserved.
••
••
••
••
••
••
••
••
••

More Related Content

Similar to C panel plugin contains log4j vulnerability

A New Paradigm In Linux Debug From Viosoft
A New Paradigm In Linux Debug From ViosoftA New Paradigm In Linux Debug From Viosoft
A New Paradigm In Linux Debug From Viosoft
guestc28df4
 
A New Paradigm In Linux Debug From Viosoft Corporation
A New Paradigm In Linux Debug From Viosoft CorporationA New Paradigm In Linux Debug From Viosoft Corporation
A New Paradigm In Linux Debug From Viosoft Corporation
art_lee
 
Enterprise Integration Patterns with ActiveMQ
Enterprise Integration Patterns with ActiveMQEnterprise Integration Patterns with ActiveMQ
Enterprise Integration Patterns with ActiveMQ
Rob Davies
 
WP_Open-Source_Best_pratice_web
WP_Open-Source_Best_pratice_webWP_Open-Source_Best_pratice_web
WP_Open-Source_Best_pratice_web
Paul Plaquette
 

Similar to C panel plugin contains log4j vulnerability (20)

Dependency check
Dependency checkDependency check
Dependency check
 
Developer-Friendly CI / CD for Kubernetes
Developer-Friendly CI / CD for KubernetesDeveloper-Friendly CI / CD for Kubernetes
Developer-Friendly CI / CD for Kubernetes
 
Apache web-server-security
Apache web-server-securityApache web-server-security
Apache web-server-security
 
News Bytes - May by corrupt
News Bytes - May by corruptNews Bytes - May by corrupt
News Bytes - May by corrupt
 
A New Paradigm In Linux Debug From Viosoft
A New Paradigm In Linux Debug From ViosoftA New Paradigm In Linux Debug From Viosoft
A New Paradigm In Linux Debug From Viosoft
 
Internship msc cs
Internship msc csInternship msc cs
Internship msc cs
 
A New Paradigm In Linux Debug From Viosoft Corporation
A New Paradigm In Linux Debug From Viosoft CorporationA New Paradigm In Linux Debug From Viosoft Corporation
A New Paradigm In Linux Debug From Viosoft Corporation
 
final doc
final docfinal doc
final doc
 
Manual 5
Manual 5Manual 5
Manual 5
 
Enterprise Integration Patterns with ActiveMQ
Enterprise Integration Patterns with ActiveMQEnterprise Integration Patterns with ActiveMQ
Enterprise Integration Patterns with ActiveMQ
 
Kali linux 2021.2
Kali linux 2021.2Kali linux 2021.2
Kali linux 2021.2
 
CIP for PCI 4.0 Release Notes for ArcSight Logger
CIP for PCI 4.0 Release Notes for ArcSight LoggerCIP for PCI 4.0 Release Notes for ArcSight Logger
CIP for PCI 4.0 Release Notes for ArcSight Logger
 
Drupal Dev Days Vienna 2023 - What is the secure software supply chain and th...
Drupal Dev Days Vienna 2023 - What is the secure software supply chain and th...Drupal Dev Days Vienna 2023 - What is the secure software supply chain and th...
Drupal Dev Days Vienna 2023 - What is the secure software supply chain and th...
 
Long Term Support the Eclipse Way
Long Term Support the Eclipse WayLong Term Support the Eclipse Way
Long Term Support the Eclipse Way
 
Using galen framework for automated cross browser layout testing
Using galen framework for automated cross browser layout testingUsing galen framework for automated cross browser layout testing
Using galen framework for automated cross browser layout testing
 
WP_Open-Source_Best_pratice_web
WP_Open-Source_Best_pratice_webWP_Open-Source_Best_pratice_web
WP_Open-Source_Best_pratice_web
 
All You need to Know about Secure Coding with Open Source Software
All You need to Know about Secure Coding with Open Source SoftwareAll You need to Know about Secure Coding with Open Source Software
All You need to Know about Secure Coding with Open Source Software
 
Laravel 9_ Unlock the Exciting Features Here!.pptx
Laravel 9_ Unlock the Exciting Features Here!.pptxLaravel 9_ Unlock the Exciting Features Here!.pptx
Laravel 9_ Unlock the Exciting Features Here!.pptx
 
OpenCL Overview Japan Virtual Open House Feb 2021
OpenCL Overview Japan Virtual Open House Feb 2021OpenCL Overview Japan Virtual Open House Feb 2021
OpenCL Overview Japan Virtual Open House Feb 2021
 
November Patch Tuesday Analysis
November Patch Tuesday AnalysisNovember Patch Tuesday Analysis
November Patch Tuesday Analysis
 

More from Temok IT Services

More from Temok IT Services (20)

what-is-machine-learning-and-its-importance-in-todays-world.pdf
what-is-machine-learning-and-its-importance-in-todays-world.pdfwhat-is-machine-learning-and-its-importance-in-todays-world.pdf
what-is-machine-learning-and-its-importance-in-todays-world.pdf
 
what-is-datafication-and-why-is-it-the-future-of-business-in-2023.pdf
what-is-datafication-and-why-is-it-the-future-of-business-in-2023.pdfwhat-is-datafication-and-why-is-it-the-future-of-business-in-2023.pdf
what-is-datafication-and-why-is-it-the-future-of-business-in-2023.pdf
 
top-9-web-hosting-trends-and-how-they-affect-your-business.pdf
top-9-web-hosting-trends-and-how-they-affect-your-business.pdftop-9-web-hosting-trends-and-how-they-affect-your-business.pdf
top-9-web-hosting-trends-and-how-they-affect-your-business.pdf
 
Computing power technology – an overview.pdf
Computing power technology – an overview.pdfComputing power technology – an overview.pdf
Computing power technology – an overview.pdf
 
Hosted VS Cloud Services key Differences; How Does It Work.pdf
Hosted VS Cloud Services key Differences; How Does It Work.pdfHosted VS Cloud Services key Differences; How Does It Work.pdf
Hosted VS Cloud Services key Differences; How Does It Work.pdf
 
35+ Frequently Asked UX Interview Questions In 2022.pdf
35+ Frequently Asked UX Interview Questions In 2022.pdf35+ Frequently Asked UX Interview Questions In 2022.pdf
35+ Frequently Asked UX Interview Questions In 2022.pdf
 
8 Digital Marketing Tools used by Experts In 2022.pdf
8 Digital Marketing Tools used by Experts In 2022.pdf8 Digital Marketing Tools used by Experts In 2022.pdf
8 Digital Marketing Tools used by Experts In 2022.pdf
 
how-to-make-money-with-nft.pdf
how-to-make-money-with-nft.pdfhow-to-make-money-with-nft.pdf
how-to-make-money-with-nft.pdf
 
Learn About The Upcoming Techniques Web 3.0 VS Web 4.0.pdf
Learn About The Upcoming Techniques Web 3.0 VS Web 4.0.pdfLearn About The Upcoming Techniques Web 3.0 VS Web 4.0.pdf
Learn About The Upcoming Techniques Web 3.0 VS Web 4.0.pdf
 
Key Differences Between Node JS vs JavaScript.pdf
Key Differences Between Node JS vs JavaScript.pdfKey Differences Between Node JS vs JavaScript.pdf
Key Differences Between Node JS vs JavaScript.pdf
 
Web Server VS Application Server Understanding The Differences.pdf
Web Server VS Application Server  Understanding The Differences.pdfWeb Server VS Application Server  Understanding The Differences.pdf
Web Server VS Application Server Understanding The Differences.pdf
 
Django vs Laravel Which Backend Framework is Better & Why.pdf
Django vs Laravel Which Backend Framework is Better & Why.pdfDjango vs Laravel Which Backend Framework is Better & Why.pdf
Django vs Laravel Which Backend Framework is Better & Why.pdf
 
IPv4 vs IPv6 Know the Difference Between Two IP Versions.pdf
IPv4 vs IPv6  Know the Difference Between Two IP Versions.pdfIPv4 vs IPv6  Know the Difference Between Two IP Versions.pdf
IPv4 vs IPv6 Know the Difference Between Two IP Versions.pdf
 
50 most commonly asked windows server interview questions
50 most commonly asked windows server interview questions50 most commonly asked windows server interview questions
50 most commonly asked windows server interview questions
 
Best video-search-engines
Best video-search-enginesBest video-search-engines
Best video-search-engines
 
Is ruby on rails dead or still good choice for building apps
Is ruby on rails dead or still good choice for building appsIs ruby on rails dead or still good choice for building apps
Is ruby on rails dead or still good choice for building apps
 
Facebook reels a new revenue model for creators
Facebook reels a new revenue model for creatorsFacebook reels a new revenue model for creators
Facebook reels a new revenue model for creators
 
What is desktop virtualization and how does it work
What is desktop virtualization and how does it workWhat is desktop virtualization and how does it work
What is desktop virtualization and how does it work
 
What is private dns & how to use it on i phone, android & laptop
What is private dns & how to use it on i phone, android & laptopWhat is private dns & how to use it on i phone, android & laptop
What is private dns & how to use it on i phone, android & laptop
 
10 server security hacks to secure your web servers
10 server security hacks to secure your web servers10 server security hacks to secure your web servers
10 server security hacks to secure your web servers
 

Recently uploaded

Call Girls in Saket (delhi) call me [9818683771 ] escort service 24X7
Call Girls in Saket (delhi) call me [9818683771 ] escort service 24X7Call Girls in Saket (delhi) call me [9818683771 ] escort service 24X7
Call Girls in Saket (delhi) call me [9818683771 ] escort service 24X7
soniya singh
 
Girls For Night in Islamabad | 03274100048 🔞
Girls For Night in Islamabad | 03274100048 🔞Girls For Night in Islamabad | 03274100048 🔞
Girls For Night in Islamabad | 03274100048 🔞
Ifra Zohaib
 
Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7
Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7
Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7
Sana Rajpoot
 

Recently uploaded (20)

Udupi Call girl service 6289102337 Udupi escort service
Udupi Call girl service 6289102337 Udupi escort serviceUdupi Call girl service 6289102337 Udupi escort service
Udupi Call girl service 6289102337 Udupi escort service
 
Bhopal ❤CALL GIRL 9874883814 ❤CALL GIRLS IN Bhopal ESCORT SERVICE❤CALL GIRL IN
Bhopal ❤CALL GIRL 9874883814 ❤CALL GIRLS IN Bhopal ESCORT SERVICE❤CALL GIRL INBhopal ❤CALL GIRL 9874883814 ❤CALL GIRLS IN Bhopal ESCORT SERVICE❤CALL GIRL IN
Bhopal ❤CALL GIRL 9874883814 ❤CALL GIRLS IN Bhopal ESCORT SERVICE❤CALL GIRL IN
 
Shimla 💋 Call Girl 9748763073 Call Girls in Shimla Escort service book now
Shimla 💋  Call Girl 9748763073 Call Girls in Shimla Escort service book nowShimla 💋  Call Girl 9748763073 Call Girls in Shimla Escort service book now
Shimla 💋 Call Girl 9748763073 Call Girls in Shimla Escort service book now
 
BARASAT CALL GIRL 7857803690 LOW PRICE ESCORT SERVICE
BARASAT CALL GIRL 7857803690  LOW PRICE  ESCORT SERVICEBARASAT CALL GIRL 7857803690  LOW PRICE  ESCORT SERVICE
BARASAT CALL GIRL 7857803690 LOW PRICE ESCORT SERVICE
 
Kanpur 💋 Call Girls 7870993772 Call Girls in Kanpur Escort service book now
Kanpur 💋 Call Girls 7870993772 Call Girls in Kanpur Escort service book nowKanpur 💋 Call Girls 7870993772 Call Girls in Kanpur Escort service book now
Kanpur 💋 Call Girls 7870993772 Call Girls in Kanpur Escort service book now
 
Call Girls in Saket (delhi) call me [9818683771 ] escort service 24X7
Call Girls in Saket (delhi) call me [9818683771 ] escort service 24X7Call Girls in Saket (delhi) call me [9818683771 ] escort service 24X7
Call Girls in Saket (delhi) call me [9818683771 ] escort service 24X7
 
Vip profile Call Girls In Hyderabad 9748763073 For Genuine Sex Service At Jus...
Vip profile Call Girls In Hyderabad 9748763073 For Genuine Sex Service At Jus...Vip profile Call Girls In Hyderabad 9748763073 For Genuine Sex Service At Jus...
Vip profile Call Girls In Hyderabad 9748763073 For Genuine Sex Service At Jus...
 
Kolkata 💋 Call Girl 9748763073 Call Girls in Kolkata Escort service book now
Kolkata 💋 Call Girl 9748763073 Call Girls in Kolkata Escort service book nowKolkata 💋 Call Girl 9748763073 Call Girls in Kolkata Escort service book now
Kolkata 💋 Call Girl 9748763073 Call Girls in Kolkata Escort service book now
 
Chennai ❣️ Call Girl 97487*63073 Call Girls in Chennai Escort service book now
Chennai ❣️ Call Girl 97487*63073 Call Girls in Chennai Escort service book nowChennai ❣️ Call Girl 97487*63073 Call Girls in Chennai Escort service book now
Chennai ❣️ Call Girl 97487*63073 Call Girls in Chennai Escort service book now
 
Call Now ☎9870417354|| Call Girls in Noida Sector 12 Escort Service Noida N.C.R.
Call Now ☎9870417354|| Call Girls in Noida Sector 12 Escort Service Noida N.C.R.Call Now ☎9870417354|| Call Girls in Noida Sector 12 Escort Service Noida N.C.R.
Call Now ☎9870417354|| Call Girls in Noida Sector 12 Escort Service Noida N.C.R.
 
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls Agency
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls AgencyHire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls Agency
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls Agency
 
Digha Call Girl Service 97487*63073 Call Girls in Digha Escort service book...
Digha  Call Girl Service 97487*63073 Call Girls in Digha  Escort service book...Digha  Call Girl Service 97487*63073 Call Girls in Digha  Escort service book...
Digha Call Girl Service 97487*63073 Call Girls in Digha Escort service book...
 
Nagpur ❤CALL GIRL 9874883814 ❤CALL GIRLS IN nagpur ESCORT SERVICE❤CALL GIRL I...
Nagpur ❤CALL GIRL 9874883814 ❤CALL GIRLS IN nagpur ESCORT SERVICE❤CALL GIRL I...Nagpur ❤CALL GIRL 9874883814 ❤CALL GIRLS IN nagpur ESCORT SERVICE❤CALL GIRL I...
Nagpur ❤CALL GIRL 9874883814 ❤CALL GIRLS IN nagpur ESCORT SERVICE❤CALL GIRL I...
 
Girls For Night in Islamabad | 03274100048 🔞
Girls For Night in Islamabad | 03274100048 🔞Girls For Night in Islamabad | 03274100048 🔞
Girls For Night in Islamabad | 03274100048 🔞
 
Berhampur Call Girl 97487*63073 Call Girls in Berhampur Escort service book now
Berhampur  Call Girl 97487*63073 Call Girls in Berhampur Escort service book nowBerhampur  Call Girl 97487*63073 Call Girls in Berhampur Escort service book now
Berhampur Call Girl 97487*63073 Call Girls in Berhampur Escort service book now
 
Jodhpur Call Girl 97487*63073 Call Girls in Jodhpur Escort service book now
Jodhpur  Call Girl 97487*63073 Call Girls in Jodhpur Escort service book nowJodhpur  Call Girl 97487*63073 Call Girls in Jodhpur Escort service book now
Jodhpur Call Girl 97487*63073 Call Girls in Jodhpur Escort service book now
 
Haldwani call girls 📞 8617697112 At Low Cost Cash Payment Booking
Haldwani call girls 📞 8617697112 At Low Cost Cash Payment BookingHaldwani call girls 📞 8617697112 At Low Cost Cash Payment Booking
Haldwani call girls 📞 8617697112 At Low Cost Cash Payment Booking
 
Bhopal ❤CALL GIRL 9874883814 ❤CALL GIRLS IN Bhopal ESCORT SERVICE❤CALL GIRL I...
Bhopal ❤CALL GIRL 9874883814 ❤CALL GIRLS IN Bhopal ESCORT SERVICE❤CALL GIRL I...Bhopal ❤CALL GIRL 9874883814 ❤CALL GIRLS IN Bhopal ESCORT SERVICE❤CALL GIRL I...
Bhopal ❤CALL GIRL 9874883814 ❤CALL GIRLS IN Bhopal ESCORT SERVICE❤CALL GIRL I...
 
Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7
Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7
Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7
 
Indore ❣️Call Girl 97487*63073 Call Girls in Indore Escort service book now
Indore  ❣️Call Girl 97487*63073 Call Girls in Indore Escort service book nowIndore  ❣️Call Girl 97487*63073 Call Girls in Indore Escort service book now
Indore ❣️Call Girl 97487*63073 Call Girls in Indore Escort service book now
 

C panel plugin contains log4j vulnerability

  • 1. Privacy - Terms cPanel Plugin Contains Log4j Vulnerability Recently, one of the most popular control panels named cPanel released a patch to correct a flaw in the log4j Java library. However, the vulnerability is known as Log4Shell and is also described as a catastrophic vulnerability by researchers. Does Log4j (CVE-2021-44228) affect cPanel? Yes, you have to uninstall the cPanel solr plugin because it is vulnerable. However, an update in version 8.8.2-4+ has been announced to mitigate CVE- 2021-44228 to the Cpanel-devecot-solr RPM. “We strongly advise all WordPress site customers running WordPress sites with IMAP messaging protocol to confirm they are running the latest version which patches this vulnerability.” Log4j Critical Log4Shell Vulnerability   0 0       0 0 3 min read cPanel Plugin Contains Log4j Vulnerability 💬 Chat with us
  • 2. Log4j is a Java library that is used for email and found in the basic cPanel plugin called cPanel Dovecot Solr plugin. It adds a drop-in functionality to many online software products. Keep in mind that it is not something that anyone would generally download and use. This plugin is a must-have component of the IMAP messaging protocol. The log4j vulnerability is the most dangerous one, which is rated at 10 on a scale of 1 to 10, where 1 is the minimum level, and 10 is the maximum. cPanel describes it as: cPanel Web Host Control Panel cPanel is the most widely used and easy-to-use web hosting control panel that allows business owner or developers to easily manage their website hosting environment.  “The cPanel Solr plugin enables Internet Message Access Protocol (IMAP) full-text search (FTS) indexing (powered by Apache Solr ™), which provides fast search capabilities for IMAP mailboxes.”
  • 3. cPanel offers a graphical user interface (GUI) like windows over dos OS, and it is also similar to a desktop interface. If you are a non-tech person, you can also perform tasks like PHP version update, checking firewalls, and adding SSL certificates, among others. According to research conducted by BuiltWith, more than 3 million users have installed cPanel to manage their hosting. United States Government Statement on Log4Shell Vulnerability The US Government Cybersecurity and Infrastructure Security Agency (CISA) published a statement on November 11, 2021, urging software developers and vendors that patch/update the log4j library in their products and for the vendors to inform their customers. The Director of CISA, Jen Easterly, wrote: Usually, end users totally rely on their software vendors, and it is compulsory for the vendors to update their community and take possible steps such as identifying, mitigating, and patching their products.  “CISA is working closely with our public and private sector partners to proactively address a critical vulnerability affecting products containing the log4j software library.”
  • 4. The statement says that the Joint Cyber Defense Collaborative, National Security Agency, and the FBI are also coordinatively working towards creating awareness and its mitigation process proactively. This statement includes: Mitigation Process for CVE-2021-44228 It was officially announced on the cPanel discussion forum that cPanel contained the log4j library, and it can be a security risk. However, you can check if this RPM is installed by executing the following command: RPM-based versions Ubuntu-based versions Example – if installed: For more detailed information: Visit our recent announcement about Log4j Vulnerability for more details.  “We continue to urge all organizations to review the latest CISA current activity alert and upgrade to log4j version 2.15.0 or apply their appropriate vendor recommended mitigations immediately. To be clear, this vulnerability poses a severe risk. We will only minimize potential impacts through collaborative efforts between the government and the private sector. We urge all organizations to join us in this essential effort and take action.” 1 # rpm -q cpanel-dovecot-solr --changelog | grep CVE-2021-44228 1 # zgrep -E CVE-2021-44228 /usr/share/doc/cpanel-dovecot-solr/changelog.Debian.gz 1 # rpm -q cpanel-dovecot-solr 1 cpanel-dovecot-solr-8.8.2-4.11.1.cpanel.noarch
  • 5. Please try to patch it ASAP and share your valuable feedback with us, and we would love to answer your questions in the comment section below. Show Comments   0 0       0 0   Get started Services Want to Start Hosting on the Cloud or Looking for the Managed Dedicated Servers ? You are on the right Place ..... +1
  • 6. Managed Dedicated Servers Managed DigitalOcean Cloud Managed Magento Cloud Managed Amazon Cloud (AWS) Managed PHP Cloud Managed Laravel Cloud Managed Drupal Cloud Managed Joomla Cloud Managed Prestashop Cloud Managed WooCommerce Cloud Managed WordPress Cloud Linux Shared Hosting Windows Shared Hosting Linux Reseller Hosting Linux SEO Hosting Domains Linux Virtual Private Server (VPS) Windows Virtual Private Server (VPS) SEO RDP/VPS Proxies VPN SSL •• •• •• •• •• •• •• •• •• •• •• •• •• •• •• •• •• •• •• •• •• ••
  • 7. Company About Us Contact Us Privacy Policy Terms & Conditions Service Level Agreement DMCA Acceptable Use Policy Blog Affiliates Subscribe Newsletter Sign up for special offers: Copyright TEMOK 2021. All Rights Reserved. •• •• •• •• •• •• •• •• ••