DNN Forums

Ask questions about your website to get help learning DNN and help resolve issues.

Log4j vulnerability

Sort:
You are not authorized to post a reply.





New Around Here





    Hi,

    We have DNN version 08.05.00 installed for our website and with the Log4j vulnerability making everyone nervous, the security team in my company is looking for an official word on if DNN can be impacted by this. Looking at the details for the vulnerability I doubt that it can impact us but can someone from the team reply an confirm?

    Thanks,

    Sumit






    New Around Here





      Inquiring minds want to know! IMO probably not, since there don't appear to be any java components in DNN. That said I wonder if IIS or other server components use this component for logging? Please correct me if I am wrong!





      Advanced Member





        My understanding is that an official statement is in the works, but that DNN Platform does not use Log4j in any way. It's a .NET application and Log4j requires Java, so even a 3rd party extensions cannot introduce Log4j into DNN (though 3rd party extensions could depend on an external service that is vulnerable).
        DNN partner specializing in custom, enterprise DNN development https://engagesoftware.com/showcase





        New Around Here





          We are on version 6.02 of DNN and are in the process of upgrading. It seems that this version may use log4j. Can anyone verify that this is the case? If so, is there any mitigation around what should be done. Any help is appreciated. Have a great day!





          Veteran Member





            What Brian said above. This is valid for all DNN versions, it is based on ASP.Net, so it cannot use log4j. Anyway, if any custom or 3rd party module depends on an external service that uses log4j, this service could be vulnerable, but I have never seen such a thing (but there are things I have not seen yet...).

            If you are using a custom or 3rd party module you should ask the manufacturer/vendor. DNN itself is not affected by this exploit.

            Happy DNNing!
            Michael

            Michael Tobisch
            DNN★MVP

            dnnWerk Austria
            DNN Connect
            You are not authorized to post a reply.

            These Forums are dedicated to the discussion of DNN Platform.

            For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

            1. If you have (suspected) security issues, please DO NOT post them in the forums but instead follow the official DNN security policy
            2. No Advertising. This includes the promotion of commercial and non-commercial products or services which are not directly related to DNN.
            3. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
            4. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
            5. No Flaming or Trolling.
            6. No Profanity, Racism, or Prejudice.
            7. Site Moderators have the final word on approving / removing a thread or post or comment.
            8. English language posting only, please.

            Would you like to help us?

            Awesome! Simply post in the forums using the link below and we'll get you started.

            Get Involved