List of software (un)affected by the log4shell CVEs

June 15, 2022 · View on GitHub

About this list

0-9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

G

SupplierProductVersion (see Status)Status CVE-2021-4104Status CVE-2021-44228Status CVE-2021-45046Status CVE-2021-45105NotesLinks
GSACloud.govlink
GoogleChromeNot vulnChrome Browser releases, infrastructure and admin console are not using versions of Log4j affected by the vulnerability.link
GE DigitalAllThis advisory is available to customers only and has not been reviewed by CISA.GE Digital Advisory Link(login required)
GE Digital GridAllThis advisory is available to customers only and has not been reviewed by CISA.GE Digital Grid Advisory Link(login required)
GE Gas PowerAsset Performance Management (APM)VulnerableGE verifying workaround.GE Gas Power Advisory Link
GE Gas PowerBaseline Security Center (BSC)VulnerableVulnerability to be fixed by vendor provided workaround. No user actions necessary. Contact GE for details.GE Gas Power Advisory Link
GE Gas PowerBaseline Security Center (BSC) 2.0VulnerableVulnerability to be fixed by vendor provided workaround. No user actions necessary. Contact GE for detailsGE Gas Power Advisory Link
GE Gas PowerControl ServerVulnerableThe Control Server is Affected via vCenter. There is a fix for vCenter. Please see below. GE verifying the vCenter fix as proposed by the vendor.GE Gas Power Advisory Link
GE Gas PowerTag Mapping ServiceNot vulnFixVulnerability fixed. No user actions necessary. Updated to log4j 2.16GE Gas Power Advisory Link
GE HealthcareAllThis advisory is not available at the time of this review, due to maintence on the GE Healthcare website.GE Healthcare Advisory Link
GearsetAllGearset Statement
GenesysAllInvestigationsource
GeoServerAllGeoServer Announcement
GeoSolutionsGeonetworkAllNot vulnWorkaroundsource
GeoSolutionsGeoServerAllNot vulnNot vulnNot vulnNot vulnsource
Gerrit code reviewAllGerrit Statement
GFIAllGFI Statement
GFI SoftwareKerio Connect9.3.1p2Not vulnWorkaroundVulnerableVulnerablesource
GhidraAllGhidra Statement
GhislerTotal CommanderAllNot vulnThird Party plugins might contain log4jsource
GigamonFabric Manager<5.13.01.02Not vulnFixUpdates available via the Gigamon Support Portal. This advisory available to customers only and has not been reviewed by CISA.Gigamon Customer Support Portal
GitHubAllGitHub.com and GitHub Enterprise CloudNot vulnFixGitHub Statement
GitHubGithub Enterprise Server3.3.1, 3.2.6, 3.1.14, 3.0.22Not vulnFixsource
GitLabAllNot vulnNot vulnNot vulnNot vulnsource
GitLabDAST analyzerNot vulnNot vulnNot vulnNot vulnsource
GitLabDependency ScanningNot vulnFixsource
GitLabGemnasium-MavenNot vulnFixsource
GitLabPMD OSSNot vulnFixsource
GitLabSASTNot vulnFixsource
GitLabSpotbugsNot vulnFixsource
GlobusAllGlobus Statement
GoAnywhereAgentsNot vulnWorkaroundsource
GoAnywhereGatewayversion 2.7.0 or laterNot vulnFixsource
GoAnywhereMFTversion 5.3.0 or laterNot vulnFixsource
GoAnywhereMFT Agents1.4.2 or laterVulnerableVersions less than GoAnywhere Agent version 1.4.2 are not affectedsource
GoAnywhereOpen PGP StudioNot vulnWorkaroundsource
GoAnywhereSurveyor/400Not vulnNot vulnNot vulnNot vulnsource
GoCDAllGoCD Statement
Google CloudAccess TransparencyNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudActifioNot vulnNot vulnNot vulnNot vulnActifio has identified limited exposure to the Log4j 2 vulnerability and has released a hotfix to address this vulnerability. Visit https://now.actifio.com https://now.actifio.com for the full statement and to obtain the hotfix (available to Actifio customers only).source
Google CloudAI Platform Data LabelingNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAI Platform Neural Architecture Search (NAS)Not vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAI Platform Training and PredictionNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAnthosNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Anthos environments to identify components dependent on Log4j 2 and update them to the latest version.source
Google CloudAnthos Config ManagementNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAnthos ConnectNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAnthos HubNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAnthos Identity ServiceNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAnthos on VMWareNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. We strongly encourage customers to check VMware recommendations documented in VMSA-2021-0028 and deploy fixes or workarounds to their VMware products as they become available. We also recommend customers review their respective applications and workloads affected by the same vulnerabilities and apply appropriate patches.source
Google CloudAnthos Premium SoftwareNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAnthos Service MeshNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudApigeeNot vulnNot vulnNot vulnNot vulnApigee installed Log4j 2 in its Apigee Edge VMs, but the software was not used and therefore the VMs were not impacted by the issues in CVE-2021-44228 and CVE-2021-45046. Apigee updated Log4j 2 to v.2.16 as an additional precaution. It is possible that customers may have introduced custom resources that are using vulnerable versions of Log4j. We strongly encourage customers who manage Apigee environments to identify components dependent on Log4j and update them to the latest version. Visit the Apigee Incident Report for more information.source
Google CloudApp EngineNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage App Engine environments to identify components dependent on Log4j 2 and update them to the latest version.source
Google CloudAppSheetNot vulnNot vulnNot vulnNot vulnThe AppSheet core platform runs on non-JVM (non-Java) based runtimes. At this time, we have identified no impact to core AppSheet functionality. Additionally, we have patched one Java-based auxiliary service in our platform. We will continue to monitor for affected services and patch or remediate as required. If you have any questions or require assistance, contact AppSheet Support.source
Google CloudArmorNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudArmor Managed Protection PlusNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudArtifact RegistryNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAssured WorkloadsNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAutoMLNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAutoML Natural LanguageNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAutoML TablesNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAutoML TranslationNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAutoML VideoNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudAutoML VisionNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudBigQueryNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudBigQuery Data Transfer ServiceNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudBigQuery OmniNot vulnNot vulnNot vulnNot vulnBigQuery Omni, which runs on AWS and Azure infrastructure, does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. We continue to work with AWS and Azure to assess the situation.source
Google CloudBinary AuthorizationNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCertificate ManagerNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudChronicleNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud Asset InventoryNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud BigtableNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud BuildNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Cloud Build environments to identify components dependent on Log4j 2 and update them to the latest version.source
Google CloudCloud CDNNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud ComposerNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Cloud Composer does not use Log4j 2 and is not impacted by the issues in CVE-2021-44228 and CVE-2021-45046. It is possible that customers may have imported or introduced other dependencies via DAGs, installed PyPI modules, plugins, or other services that are using vulnerable versions of Log4j 2. We strongly encourage customers, who manage Composer environments to identify components dependent on Log4j 2 and update them to the latest version.source
Google CloudCloud Console AppNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud Data Loss PreventionNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud DebuggerNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud Deployment ManagerNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud DNSNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud EndpointsNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud External Key Manager (EKM)Not vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud FunctionsNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Cloud Functions environments to identify components dependent on Log4j 2 and update them to the latest version.source
Google CloudCloud Harware Security Module (HSM)Not vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud InterconnectNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud Intrusion Detection System (IDS)Not vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud Key Management ServiceNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud Load BalancingNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud LoggingNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud Natural Language APINot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud Network Address Translation (NAT)Not vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud ProfilerNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud RouterNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud Run12/21/2021
Google CloudCloud Run for AnthosNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Cloud Run for Anthos environments to identify components dependent on Log4j 2 and update them to the latest version.source
Google CloudCloud SchedulerNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud SDKNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud ShellNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Cloud Shell environments to identify components dependent on Log4j 2 and update them to the latest version.source
Google CloudCloud Source RepositoriesNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud SpannerNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud SQLNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud StorageNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud TasksNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud TraceNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud Traffic DirectorNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud TranslationNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud VisionNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud Vision OCR On-PremNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCloud VPNNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCompilerWorksNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudCompute EngineNot vulnNot vulnNot vulnNot vulnCompute Engine does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. For those using Google Cloud VMware Engine, we are working with VMware and tracking VMSA-2021-0028.1. We will deploy fixes to Google Cloud VMware Engine as they become available.source
Google CloudContact Center AI (CCAI)Not vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudContact Center AI InsightsNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudContainer RegistryNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudData CatalogNot vulnNot vulnNot vulnNot vulnData Catalog has been updated to mitigate the issues identified in CVE-2021-44228 and CVE-2021-45046. We strongly encourage customers who introduced their own connectors to identify dependencies on Log4j 2 and update them to the latest version.source
Google CloudData FusionNot vulnNot vulnNot vulnNot vulnData Fusion does not use Log4j 2, but uses Dataproc as one of the options to execute pipelines. Dataproc released new images on December 18, 2021 to address the vulnerability in CVE-2021-44228 and CVE-2021-45046. Customers must follow instructions in a notification sent on December 18, 2021 with the subject line “Important information about Data Fusion.”source
Google CloudDatabase Migration Service (DMS)Not vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudDataflowNot vulnNot vulnNot vulnNot vulnDataflow does not use Log4j 2 and is not impacted by the issues in CVE-2021-44228 and CVE-2021-45046. If you have changed dependencies or default behavior, it is strongly recommended you verify there is no dependency on vulnerable versions Log4j 2. Customers have been provided details and instructions in a notification sent on December 17, 2021 with the subject line “Update #1 to Important information about Dataflow.”source
Google CloudDataprocNot vulnNot vulnNot vulnNot vulnDataproc released new images on December 18, 2021 to address the vulnerabilities in CVE-2021-44228 and CVE-2021-45046. Customers must follow the instructions in notifications sent on December 18, 2021 with the subject line “Important information about Dataproc” with Dataproc documentation.source
Google CloudDataproc MetastoreNot vulnNot vulnNot vulnNot vulnDataproc Metastore has been updated to mitigate the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers who need to take actions were sent two notifications with instructions on December 17, 2021 with the subject line “Important information regarding Log4j 2 vulnerability in your gRPC-enabled Dataproc Metastore.”source
Google CloudDatastoreNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudDatastreamNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudDialogflow Essentials (ES)Not vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudDocument AINot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudEvent Threat DetectionNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudEventarcNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudFilestoreNot vulnNot vulnNot vulnNot vulnLog4j 2 is contained within the Filestore service; there is a technical control in place that mitigates the vulnerabilities in CVE-2021-44228 and CVE-2021-45046. Log4j 2 will be updated to the latest version as part of the scheduled rollout in January 2022.source
Google CloudFirebaseNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudFirestoreNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudGame ServersNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudGoogle Kubernetes EngineNot vulnNot vulnNot vulnNot vulnGoogle Kubernetes Engine does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Google Kubernetes Engine environments to identify components dependent on Log4j 2 and update them to the latest version.source
Google CloudHealthcare Data Engine (HDE)Not vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudHuman-in-the-Loop AINot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudIoT CoreNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudKey Access Justifications (KAJ)Not vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudLookerNot vulnNot vulnNot vulnNot vuln\Looker-hosted instances have been updated to a Looker version with Log4j v2.16. Looker is currently working with third-party driver vendors to evaluate the impact of the Log4j vulnerability. As Looker does not enable logging for these drivers in Looker-hosted instances, no messages are logged. We conclude that the vulnerability is mitigated. We continue to actively work with the vendors to deploy a fix for these drivers. Looker customers who self-manage their Looker instances have received instructions through their technical contacts on how to take the necessary steps to address the vulnerability. Looker customers who have questions or require assistance, please visit Looker Support.source
Google CloudMedia Translation APINot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudMemorystoreNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudMigrate for AnthosNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudMigrate for Compute Engine (M4CE)Not vulnNot vulnNot vulnNot vulnM4CE has been updated to mitigate the issues identified in CVE-2021-44228 and CVE-2021-45046. M4CE has been updated to version 4.11.9 to address the vulnerabilities. A notification was sent to customers on December 17, 2021 with subject line “Important information about CVE-2021-44228 and CVE-2021-45046” for M4CE V4.11 or below. If you are on M4CE v5.0 or above, no action is needed.source
Google CloudNetwork Connectivity CenterNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudNetwork Intelligence CenterNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudNetwork Service TiersNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudPersistent DiskNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudPub/SubNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudPub/Sub LiteNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Pub/Sub Lite environments to identify components dependent on Log4j 2 and update them to the latest version.source
Google CloudreCAPTCHA EnterpriseNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudRecommendations AINot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudRetail SearchNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudRisk ManagerNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudSecret ManagerNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudSecurity Command CenterNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudService DirectoryNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudService InfrastructureNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudSpeaker IDNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudSpeech-to-TextNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudSpeech-to-Text On-PremNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudStorage Transfer ServiceNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudTalent SolutionNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudText-to-SpeechNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudTranscoder APINot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudTransfer ApplianceNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudVideo Intelligence APINot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudVirtual Private CloudNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudVMware EngineNot vulnNot vulnNot vulnNot vulnWe are working with VMware and tracking VMSA-2021-0028.1. We will deploy fixes as they become available.source
Google CloudWeb Security ScannerNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
Google CloudWorkflowsNot vulnNot vulnNot vulnNot vulnProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.source
GradleAllNot vulnNot vulnNot vulnNot vulnGradle Scala Compiler Plugin depends upon log4j-core but it is not used.source
GradleEnterprise2021.3.6Not vulnFixsource
GradleEnterprise Build Cache Node10.1Not vulnFixsource
GradleEnterprise Test Distribution Agent1.6.2Not vulnFixsource
GrafanaAllNot vulnNot vulnNot vulnNot vulnsource
GrandstreamAllGrandstream Statement
GraviteeAccess Management3.10.xNot vulnNot vulnNot vulnNot vulnAbout the Log4J CVSS 10 Critical Vulnerability
GraviteeAccess Management3.5.xNot vulnNot vulnNot vulnNot vulnAbout the Log4J CVSS 10 Critical Vulnerability
GraviteeAlert Engine1.4.xNot vulnNot vulnNot vulnNot vulnAbout the Log4J CVSS 10 Critical Vulnerability
GraviteeAlert Engine1.5.xNot vulnNot vulnNot vulnNot vulnAbout the Log4J CVSS 10 Critical Vulnerability
GraviteeAPI Management3.10.xNot vulnNot vulnNot vulnNot vulnAbout the Log4J CVSS 10 Critical Vulnerability
GraviteeAPI Management3.5.xNot vulnNot vulnNot vulnNot vulnAbout the Log4J CVSS 10 Critical Vulnerability
GraviteeCockpit1.4.xNot vulnNot vulnNot vulnNot vulnAbout the Log4J CVSS 10 Critical Vulnerability
Gravitee.ioAllGravitee.io Statement
GravwellAllNot vulnNot vulnNot vulnNot vulnGravwell products do not use Javasource
GraylogAll3.3.15, 4.0.14, 4.1.9, 4.2.3Not vulnFixThe vulnerable Log4j library is used to record GrayLog's own log information. Vulnerability is not triggered when GrayLog stores exploitation vector from an outer system. Graylog https://github.com/Graylog2/graylog2-server/compare/4.2.3...4.2.4"">version 4.2.4 fixes https://www.lunasec.io/docs/blog/log4j-zero-day-update-on-cve-2021-45046/ another vulnerabilitysource
GraylogServerAll versions >= 1.2.0 and <= 4.2.2Not vulnFixGraylog Update for Log4j
GreenshotAllNot vulnNot vulnNot vulnNot vulnsource
GuardedBoxAll3.1.2Not vulnFixsource
GuidewireAllGuidewire Statement