Blog | Topicus KeyHub

Topicus KeyHub is not vulnerable to CVE-2021-44228 (log4shell)

Geschreven door Sven Haster | 12/12/2021

Topicus KeyHub does not depend on Log4j2 and is therefore not vulnerable to CVE-2021-44228.

While Topicus KeyHub is a Java webapplication, it uses a different logging implementation. The Log4j APIs are included with the application container, but a separate logging system is used as the implementation. This logging system does not include the affected JNDI lookup capability.