CISA Log4j (CVE-2021-44228) Affected Vendor & Software List

March 1, 2022 · View on GitHub

0-9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Status Descriptions

StatusDescription
UnknownStatus unknown. Default choice.
AffectedReported to be affected by CVE-2021-44228.
Not AffectedReported to NOT be affected by CVE-2021-44228 and no further action necessary.
FixedPatch and/or mitigations available (see provided links).
Under InvestigationVendor investigating status.

Software List

This list has been populated using information from the following sources:

  • Kevin Beaumont
  • SwitHak
  • National Cyber Security Centre - Netherlands (NCSC-NL)

NOTE: This file is automatically generated. To submit updates, please refer to CONTRIBUTING.md.

VendorProductAffected VersionsPatched VersionsStatusVendor LinksNotesReferencesReporterLast Updated
GE DigitalAllUnknownlinkThis advisory is available to customers only and has not been reviewed by CISA.cisagov2021-12-22
GE Digital GridAllUnknownlinkThis advisory is available to customers only and has not been reviewed by CISA.cisagov2021-12-22
GE Gas PowerAsset Performance Management (APM)FixedlinkGE Digital has fixed the log4j issue on the APM. Validation and test completed in development environment and the team is currently deploying the fixes in the production environment.cisagov2021-12-22
GE Gas PowerBaseline Security Center (BSC)AffectedlinkGE Gas Power is still validating the workaround provided by FoxGuard in Technical Information Notice – M1221-S01.cisagov2021-12-22
GE Gas PowerBaseline Security Center (BSC) 2.0FixedlinkGE Gas Power has tested and validated the component of the BSC 2.0 that is impacted (McAfee SIEM 11.x). The update and instructions can be downloaded from link in reference section. This update is available to customer only and has not been reviewed by CISA.Customer Portal Updatecisagov2021-12-22
GE Gas PowerControl ServerAffectedlinkPlease see vCenter. Control Server is not directly impacted. It is impacted through vCenter.cisagov2021-12-22
GE Gas PowerMyFleetFixedlinkVulnerability fixed. No user actions necessary. Updated to log4j 2.16cisagov2021-12-22
GE Gas PowerOPM Performance IntelligenceFixedlinkVulnerability fixed. No user actions necessary. Updated to log4j 2.16cisagov2021-12-22
GE Gas PowerOPM Performance PlanningFixedlinkVulnerability fixed. No user actions necessary. Updated to log4j 2.16cisagov2021-12-22
GE Gas PowerTag Mapping ServiceFixedlinkVulnerability fixed. No user actions necessary. Updated to log4j 2.16cisagov2021-12-22
GE Gas PowervCenterFixedlinkGE Gas Power has tested and validated the update provided by Vmware. The update and instructions can be downloaded from link in reference section. This update is available to customer only and has not been reviewed by CISA.Customer Portal Updatecisagov2021-12-22
GE HealthcareUnknownlinkThis advisory is not available at the time of this review, due to maintence on the GE Healthcare website.cisagov2021-12-22
GearsetAllUnknownlinkcisagov2022-01-12
GenesysAllUnknownlinkcisagov2022-01-12
GeoServerAllUnknownlinkcisagov2022-01-12
GeoSolutionsGeoNetworkA, l, lFixedlinkcisagov2021-12-16
GeoSolutionsGeoServerNot Affectedlinkcisagov2021-12-16
Gerrit Code ReviewAllUnknownlinkcisagov2022-01-12
GFI SoftwareAllUnknownlinkcisagov2022-01-12
GFI SoftwareKerio ConnectFixedlinkcisagov2022-01-12
GhidraAllUnknownlinkcisagov2022-01-12
GhislerTotal CommanderNot AffectedlinkThird Party plugins might contain log4j.cisagov2022-01-12
GigamonFabric Manager<5.13.01.02FixedlinkUpdates available via the Gigamon Support Portal. This advisory available to customers only and has not been reviewed by CISA.cisagov2021-12-21
GitHubGitHubGitHub.com and GitHub Enterprise CloudFixedlinkcisagov2021-12-17
GitHubGitHub Enterprise Server3.0.22, 3.1.14, 3.2.6, 3.3.1Fixedlinkcisagov2021-12-17
GitLabAllNot Affectedlinkcisagov2022-01-12
GitLabDAST AnalyzerNot Affectedlinkcisagov2022-01-12
GitLabDependency ScanningFixedlinkcisagov2022-01-12
GitLabGemnasium-MavenFixedlinkcisagov2022-01-12
GitLabPMD OSSFixedlinkcisagov2022-01-12
GitLabSASTFixedlinkcisagov2022-01-12
GitLabSpotbugsFixedlinkcisagov2022-01-12
GlobusAllUnknownlinkcisagov2022-01-12
GoAnywhereAgentsFixedlinkcisagov2021-12-18
GoAnywhereGatewayVersion 2.7.0 or laterFixedlinkcisagov2021-12-18
GoAnywhereMFTVersion 5.3.0 or laterFixedlinkcisagov2021-12-18
GoAnywhereMFT Agents1.4.2 or laterAffectedlinkVersions less than GoAnywhere Agent version 1.4.2 are not affected.cisagov2021-12-18
GoAnywhereOpen PGP StudioFixedlinkcisagov2021-12-18
GoAnywhereSuveyor/400Not Affectedlinkcisagov2021-12-18
GoCDAllUnknownlinkcisagov2022-01-12
GoogleChromeNot AffectedlinkChrome Browser releases, infrastructure and admin console are not using versions of Log4j affected by the vulnerability.cisagov2022-01-14
Google CloudAccess TransparencyNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudActifioNot AffectedlinkActifio has identified limited exposure to the Log4j 2 vulnerability and has released a hotfix to address this vulnerability. Visit https://now.actifio.com for the full statement and to obtain the hotfix (available to Actifio customers only).cisagov2021-12-21
Google CloudAI Platform Data LabelingNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAI Platform Neural Architecture Search (NAS)Not AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAI Platform Training and PredictionNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAnthosNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Anthos environments to identify components dependent on Log4j 2 and update them to the latest version.cisagov2021-12-21
Google CloudAnthos Config ManagementNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAnthos ConnectNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAnthos HubNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAnthos Identity ServiceNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAnthos on VMWareNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. We strongly encourage customers to check VMware recommendations documented in VMSA-2021-0028 and deploy fixes or workarounds to their VMware products as they become available. We also recommend customers review their respective applications and workloads affected by the same vulnerabilities and apply appropriate patches.cisagov2021-12-21
Google CloudAnthos Premium SoftwareNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAnthos Service MeshNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudApigeeNot AffectedlinkApigee installed Log4j 2 in its Apigee Edge VMs, but the software was not used and therefore the VMs were not impacted by the issues in CVE-2021-44228 and CVE-2021-45046. Apigee updated Log4j 2 to v.2.16 as an additional precaution. It is possible that customers may have introduced custom resources that are using vulnerable versions of Log4j. We strongly encourage customers who manage Apigee environments to identify components dependent on Log4j and update them to the latest version. Visit the Apigee Incident Report for more information.cisagov2021-12-17
Google CloudApp EngineNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage App Engine environments to identify components dependent on Log4j 2 and update them to the latest version.cisagov2021-12-21
Google CloudAppSheetNot AffectedlinkThe AppSheet core platform runs on non-JVM (non-Java) based runtimes. At this time, we have identified no impact to core AppSheet functionality. Additionally, we have patched one Java-based auxiliary service in our platform. We will continue to monitor for affected services and patch or remediate as required. If you have any questions or require assistance, contact AppSheet Support.cisagov2021-12-21
Google CloudArtifact RegistryNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAssured WorkloadsNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAutoMLNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAutoML Natural LanguageNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAutoML TablesNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAutoML TranslationNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAutoML VideoNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudAutoML VisionNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudBigQueryNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudBigQuery Data Transfer ServiceNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudBigQuery OmniNot AffectedlinkBigQuery Omni, which runs on AWS and Azure infrastructure, does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. We continue to work with AWS and Azure to assess the situation.cisagov2021-12-19
Google CloudBinary AuthorizationNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCertificate ManagerNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudChronicleNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudCloud Asset InventoryNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud BigtableNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-19
Google CloudCloud BuildNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Cloud Build environments to identify components dependent on Log4j 2 and update them to the latest version.cisagov2021-12-21
Google CloudCloud CDNNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudCloud ComposerNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Cloud Composer does not use Log4j 2 and is not impacted by the issues in CVE-2021-44228 and CVE-2021-45046. It is possible that customers may have imported or introduced other dependencies via DAGs, installed PyPI modules, plugins, or other services that are using vulnerable versions of Log4j 2. We strongly encourage customers, who manage Composer environments to identify components dependent on Log4j 2 and update them to the latest version.cisagov2021-12-15
Google CloudCloud Console AppNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud Data Loss PreventionNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud DebuggerNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud Deployment ManagerNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud DNSNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudCloud EndpointsNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud External Key Manager (EKM)Not AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud FunctionsNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Cloud Functions environments to identify components dependent on Log4j 2 and update them to the latest version.cisagov2021-12-21
Google CloudCloud Hardware Security Module (HSM)Not AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud InterconnectNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud Intrusion Detection System (IDS)Not AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud Key Management ServiceNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud Load BalancingNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudCloud LoggingNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud Natural Language APINot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud Network Address Translation (NAT)Not AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudCloud ProfilerNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud RouterNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudCloud RunNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Cloud Run environments to identify components dependent on Log4j 2 and update them to the latest version.cisagov2021-12-21
Google CloudCloud Run for AnthosNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Cloud Run for Anthos environments to identify components dependent on Log4j 2 and update them to the latest version.cisagov2021-12-21
Google CloudCloud SchedulerNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud SDKNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud ShellNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Cloud Shell environments to identify components dependent on Log4j 2 and update them to the latest version.cisagov2021-12-21
Google CloudCloud Source RepositoriesNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud SpannerNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-19
Google CloudCloud SQLNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-19
Google CloudCloud StorageNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudCloud TasksNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud TraceNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud Traffic DirectorNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudCloud TranslationNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud VisionNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud Vision OCR On-PremNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudCloud VPNNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudCompilerWorksNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudCompute EngineNot AffectedlinkCompute Engine does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. For those using Google Cloud VMware Engine, we are working with VMware and tracking VMSA-2021-0028.1. We will deploy fixes to Google Cloud VMware Engine as they become available.cisagov2021-12-20
Google CloudContact Center AI (CCAI)Not AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudContact Center AI InsightsNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudContainer RegistryNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudData CatalogNot AffectedlinkData Catalog has been updated to mitigate the issues identified in CVE-2021-44228 and CVE-2021-45046. We strongly encourage customers who introduced their own connectors to identify dependencies on Log4j 2 and update them to the latest version.cisagov2021-12-20
Google CloudData FusionNot AffectedlinkData Fusion does not use Log4j 2, but uses Dataproc as one of the options to execute pipelines. Dataproc released new images on December 18, 2021 to address the vulnerability in CVE-2021-44228 and CVE-2021-45046. Customers must follow instructions in a notification sent on December 18, 2021 with the subject line “Important information about Data Fusion.”cisagov2021-12-20
Google CloudDatabase Migration Service (DMS)Not AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-19
Google CloudDataflowNot AffectedlinkDataflow does not use Log4j 2 and is not impacted by the issues in CVE-2021-44228 and CVE-2021-45046. If you have changed dependencies or default behavior, it is strongly recommended you verify there is no dependency on vulnerable versions Log4j 2. Customers have been provided details and instructions in a notification sent on December 17, 2021 with the subject line “Update #1 to Important information about Dataflow.”cisagov2021-12-17
Google CloudDataprocNot AffectedlinkDataproc released new images on December 18, 2021 to address the vulnerabilities in CVE-2021-44228 and CVE-2021-45046. Customers must follow the instructions in notifications sent on December 18, 2021 with the subject line “Important information about Dataproc” with Dataproc documentation.cisagov2021-12-20
Google CloudDataproc MetastoreNot AffectedlinkDataproc Metastore has been updated to mitigate the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers who need to take actions were sent two notifications with instructions on December 17, 2021 with the subject line “Important information regarding Log4j 2 vulnerability in your gRPC-enabled Dataproc Metastore.”cisagov2021-12-20
Google CloudDatastoreNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-19
Google CloudDatastreamNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-19
Google CloudDialogflow Essentials (ES)Not AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudDocument AINot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudEvent Threat DetectionNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudEventarcNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudFilestoreNot AffectedlinkLog4j 2 is contained within the Filestore service; there is a technical control in place that mitigates the vulnerabilities in CVE-2021-44228 and CVE-2021-45046. Log4j 2 will be updated to the latest version as part of the scheduled rollout in January 2022.cisagov2021-12-21
Google CloudFirebaseNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudFirestoreNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-19
Google CloudGame ServersNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudGoogle Cloud ArmorNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudGoogle Cloud Armor Managed Protection PlusNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudGoogle Cloud VMware EngineNot AffectedlinkWe are working with VMware and tracking VMSA-2021-0028.1. We will deploy fixes as they become available.cisagov2021-12-11
Google CloudGoogle Kubernetes EngineNot AffectedlinkGoogle Kubernetes Engine does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Google Kubernetes Engine environments to identify components dependent on Log4j 2 and update them to the latest version.cisagov2021-12-21
Google CloudHealthcare Data Engine (HDE)Not AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudHuman-in-the-Loop AINot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudIoT CoreNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudKey Access Justifications (KAJ)Not AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudLookerNot AffectedlinkLooker-hosted instances have been updated to a Looker version with Log4j v2.16. Looker is currently working with third-party driver vendors to evaluate the impact of the Log4j vulnerability. As Looker does not enable logging for these drivers in Looker-hosted instances, no messages are logged. We conclude that the vulnerability is mitigated. We continue to actively work with the vendors to deploy a fix for these drivers. Looker customers who self-manage their Looker instances have received instructions through their technical contacts on how to take the necessary steps to address the vulnerability. Looker customers who have questions or require assistance, please visit Looker Support.cisagov2021-12-18
Google CloudMedia Translation APINot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudMemorystoreNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-19
Google CloudMigrate for AnthosNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudMigrate for Compute Engine (M4CE)Not AffectedlinkM4CE has been updated to mitigate the issues identified in CVE-2021-44228 and CVE-2021-45046. M4CE has been updated to version 4.11.9 to address the vulnerabilities. A notification was sent to customers on December 17, 2021 with subject line “Important information about CVE-2021-44228 and CVE-2021-45046” for M4CE V4.11 or below. If you are on M4CE v5.0 or above, no action is needed.cisagov2021-12-19
Google CloudNetwork Connectivity CenterNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudNetwork Intelligence CenterNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudNetwork Service TiersNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudPersistent DiskNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudPub/SubNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-16
Google CloudPub/Sub LiteNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046. Customers may have introduced a separate logging solution that uses Log4j 2. We strongly encourage customers who manage Pub/Sub Lite environments to identify components dependent on Log4j 2 and update them to the latest version.cisagov2021-12-16
Google CloudreCAPTCHA EnterpriseNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudRecommendations AINot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudRetail SearchNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudRisk ManagerNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudSecret ManagerNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudSecurity Command CenterNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudService DirectoryNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudService InfrastructureNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudSpeaker IDNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudSpeech-to-TextNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudSpeech-to-Text On-PremNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudStorage Transfer ServiceNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudTalent SolutionNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudText-to-SpeechNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudTranscoder APINot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudTransfer ApplianceNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudVideo Intelligence APINot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudVirtual Private CloudNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
Google CloudWeb Security ScannerNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
Google CloudWorkflowsNot AffectedlinkProduct does not use Log4j 2 and is not impacted by the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-21
GradleAllNot AffectedlinkGradle Scala Compiler Plugin depends upon log4j-core but it is not used.cisagov2022-01-12
GradleGradle Enterprise< 2021.3.6Fixedlinkcisagov2022-01-12
GradleGradle Enterprise Build Cache Node< 10.1Fixedlinkcisagov2022-01-12
GradleGradle Enterprise Test Distribution Agent< 1.6.2Fixedlinkcisagov2022-01-12
GrafanaAllNot Affectedlinkcisagov2022-01-12
GrandstreamAllUnknownlinkcisagov2022-01-12
GraviteeAccess ManagementNot Affectedlinkcisagov2022-01-12
GraviteeAccess ManagementNot Affectedlinkcisagov2022-01-12
GraviteeAlert EngineNot Affectedlinkcisagov2022-01-12
GraviteeAlert EngineNot Affectedlinkcisagov2022-01-12
GraviteeAPI ManagementNot Affectedlinkcisagov2022-01-12
GraviteeAPI ManagementNot Affectedlinkcisagov2022-01-12
GraviteeCockpitNot Affectedlinkcisagov2022-01-12
GravwellAllNot AffectedlinkGravwell products do not use Java.cisagov2022-01-12
GraylogAll3.3.15, 4.0.14, 4.1.9, 4.2.3FixedlinkThe vulnerable Log4j library is used to record GrayLogs own log information. Vulnerability is not triggered when GrayLog stores exploitation vector from an outer system.cisagov2022-01-12
GraylogGraylog ServerAll versions >= 1.2.0 and <= 4.2.2Fixedlinkcisagov2022-01-12
GreenShotAllNot Affectedlinkcisagov2022-01-12
GSACloud.govUnknownlinkcisagov2021-12-21
GuardedBoxAll3.1.2Fixedlinkcisagov2022-01-12
GuidewireAllUnknownlinkcisagov2022-01-12