<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log4J day-zero exploit CVE-2021-44228 in APIs &amp; Integrations</title>
    <link>https://community.hubspot.com/t5/APIs-Integrations/Log4J-day-zero-exploit-CVE-2021-44228/m-p/541949#M49446</link>
    <description>&lt;P&gt;Since Hubspot uses Log4J (&lt;A href="https://product.hubspot.com/blog/bid/6011/log4j-dynamic-appender-configuration" target="_blank" rel="noopener"&gt;https://product.hubspot.com/blog/bid/6011/log4j-dynamic-appender-configuration&lt;/A&gt;), does anyone knows what mitigation measures have been taken to deal with&amp;nbsp;day-zero exploit CVE-2021-44228 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HubSpot uses Cloudflare (&lt;A href="https://www.cloudflare.com/case-studies/hubspot/" target="_blank" rel="noopener"&gt;https://www.cloudflare.com/case-studies/hubspot/&lt;/A&gt;), and Cloudflare has already initiated mitigation measures (&lt;A href="https://info.cloudflare.com/index.php/email/emailWebview?mkt_tok=NzEzLVhTQy05MTgAAAGBRbAScyE5IiQgYSp2tQ7p4d5EDZ0UyLMhBv5vE_6I_EvTz_OiGDqUph7Uzi8m_XQmGeqJTeiWE5czV4HlM4-yuhRXki1vnuUQCBryUi9NEdcyUVyo&amp;amp;md_id=59712" target="_blank" rel="noopener"&gt;https://info.cloudflare.com/index.php/email/emailWebview?mkt_tok=NzEzLVhTQy05MTgAAAGBRbAScyE5IiQgYSp2tQ7p4d5EDZ0UyLMhBv5vE_6I_EvTz_OiGDqUph7Uzi8m_XQmGeqJTeiWE5czV4HlM4-yuhRXki1vnuUQCBryUi9NEdcyUVyo&amp;amp;md_id=59712&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But has HubSpot initiated some mitigation measures&amp;nbsp; by themselfs ?&lt;/P&gt;</description>
    <pubDate>Tue, 14 Dec 2021 11:08:10 GMT</pubDate>
    <dc:creator>PRDuque</dc:creator>
    <dc:date>2021-12-14T11:08:10Z</dc:date>
    <item>
      <title>Log4J day-zero exploit CVE-2021-44228</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Log4J-day-zero-exploit-CVE-2021-44228/m-p/541949#M49446</link>
      <description>&lt;P&gt;Since Hubspot uses Log4J (&lt;A href="https://product.hubspot.com/blog/bid/6011/log4j-dynamic-appender-configuration" target="_blank" rel="noopener"&gt;https://product.hubspot.com/blog/bid/6011/log4j-dynamic-appender-configuration&lt;/A&gt;), does anyone knows what mitigation measures have been taken to deal with&amp;nbsp;day-zero exploit CVE-2021-44228 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HubSpot uses Cloudflare (&lt;A href="https://www.cloudflare.com/case-studies/hubspot/" target="_blank" rel="noopener"&gt;https://www.cloudflare.com/case-studies/hubspot/&lt;/A&gt;), and Cloudflare has already initiated mitigation measures (&lt;A href="https://info.cloudflare.com/index.php/email/emailWebview?mkt_tok=NzEzLVhTQy05MTgAAAGBRbAScyE5IiQgYSp2tQ7p4d5EDZ0UyLMhBv5vE_6I_EvTz_OiGDqUph7Uzi8m_XQmGeqJTeiWE5czV4HlM4-yuhRXki1vnuUQCBryUi9NEdcyUVyo&amp;amp;md_id=59712" target="_blank" rel="noopener"&gt;https://info.cloudflare.com/index.php/email/emailWebview?mkt_tok=NzEzLVhTQy05MTgAAAGBRbAScyE5IiQgYSp2tQ7p4d5EDZ0UyLMhBv5vE_6I_EvTz_OiGDqUph7Uzi8m_XQmGeqJTeiWE5czV4HlM4-yuhRXki1vnuUQCBryUi9NEdcyUVyo&amp;amp;md_id=59712&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But has HubSpot initiated some mitigation measures&amp;nbsp; by themselfs ?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 11:08:10 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Log4J-day-zero-exploit-CVE-2021-44228/m-p/541949#M49446</guid>
      <dc:creator>PRDuque</dc:creator>
      <dc:date>2021-12-14T11:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Log4J day-zero exploit CVE-2021-44228</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Log4J-day-zero-exploit-CVE-2021-44228/m-p/542293#M49459</link>
      <description>&lt;P&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/168666"&gt;@PRDuque&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HubSpot is aware of CVE-2021-44228 and we have performed a thorough check of our systems and have seen no indications of any impact from this vulnerability at this time. Out of an abundance of caution, our team is continuing to monitor this event. Customers don't need to take any action at this time.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 19:25:53 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Log4J-day-zero-exploit-CVE-2021-44228/m-p/542293#M49459</guid>
      <dc:creator>dennisedson</dc:creator>
      <dc:date>2021-12-14T19:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: Log4J day-zero exploit CVE-2021-44228</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Log4J-day-zero-exploit-CVE-2021-44228/m-p/542308#M49460</link>
      <description>Have you updated all projects to log4j latest version, and deployed it to production?&lt;BR /&gt;</description>
      <pubDate>Tue, 14 Dec 2021 19:39:47 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Log4J-day-zero-exploit-CVE-2021-44228/m-p/542308#M49460</guid>
      <dc:creator>PRDuque</dc:creator>
      <dc:date>2021-12-14T19:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Log4J day-zero exploit CVE-2021-44228</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Log4J-day-zero-exploit-CVE-2021-44228/m-p/542423#M49466</link>
      <description>&lt;P&gt;We've published a landing page that will hopefully be helpful:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.hubspot.com/log4j2" target="_blank"&gt;https://www.hubspot.com/log4j2&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 23:43:03 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Log4J-day-zero-exploit-CVE-2021-44228/m-p/542423#M49466</guid>
      <dc:creator>jonathanhaber</dc:creator>
      <dc:date>2021-12-14T23:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: Log4J day-zero exploit CVE-2021-44228</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Log4J-day-zero-exploit-CVE-2021-44228/m-p/542588#M49474</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/212945"&gt;@jonathanhaber&lt;/a&gt;&amp;nbsp;, this is very useful.&lt;/P&gt;&lt;P&gt;Not sure if already discussed, but it would be tremendously helpful if such information could be pushed out to us admins proactively. It took me some googling to even find this thread.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 08:45:03 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Log4J-day-zero-exploit-CVE-2021-44228/m-p/542588#M49474</guid>
      <dc:creator>DSidler</dc:creator>
      <dc:date>2021-12-15T08:45:03Z</dc:date>
    </item>
  </channel>
</rss>

