CVE-2021-44228 / Log4Shell / log4j vulnerability

Is there any component within the privacyidea platform that is subject to the CVE-2021-44228 / Log4Shell / log4j vulnerability?

https://nvd.nist.gov/vuln/detail/CVE-2021-44228

1 Like

No. The privacyIDEA server is written in Python.
The only Java component is the keycloak plugin. It does not use this.

2 Likes