Few days back I received an email form VMware inviting me for a podcast. The reason for invitation was one of my posts about log4j vulnerabilities -> Additional step for vCenter Server CVE-2021-44228 and CVE-2021-45046 workaround. The reason for the article about additional step was to make a community aware of remove_log4j_class.py script. That information…
Read moreTag: log4j
vCenter Server 7.0 Update 3c has been released.
Finally, VMware released a new update for vCenter Server addressing all the issues documented in KB86281, also including Apache log4j version 2.17. IMPORTANT: VMware removed ESXi 7.0 Update 3, 7.0 Update 3a, and 7.0 Update 3b from all sites on November 19, 2021 due to an upgrade-impacting issue. Build 19193900 for ESXi 7.0 Update 3c ISO replaces build 18644231, 18825058, and 18905247 for ESXi…
Read moreIs VMware going to update log4j to version 2.17
As we know by now that the only solution for Log4j is to get it updated to version 2.17. The question is if VMware is going to update log4j to version 2.17? Here is an official answer from VMware: VMware regularly updates open-source components inside our products as new versions ship. As we’ve noted in…
Read more