Zero-day flaw log4j2 - needs patching

How do I find what version of Log4J2 we have installed and after that, how do we upgrade it?

There is a zero-day flaw that needs patching:

FYI: Zero day for log4j versions: 2.0 <= Apache log4j <= 2.14.1 https://www.lunasec.io/docs/blog/log4j-zero-day/ patch: https://github.com/apache/logging-log4j2/releases/tag/log4j-2.15.0-rc1

@angelf21

Hello,

Have we got any more info on this and the impacts?

Please share if you have got any info on how to upgrade it to 2.15.

This is the latest update from Pega.

@Anish

The latest from PEGA is on how to delete jars from database and update Pega_Stream, and that a hotfix is TBD :frowning:

Their recommendations are here: Pegasystems Documentation

As of today, the new version of log4j is actually 2.17.x