Company
Date Published
Author
Thomas Owen
Word count
275
Language
English
Hacker News points
None

Summary

In response to the Log4j RCE vulnerability CVE-2021-44228 and its related follow-up CVE-2021-45046, Grafana Labs assures its users that their core products, including Grafana OSS, Grafana Cloud, and Enterprise offerings, are not impacted due to their minimal use of Java in their stack. After a comprehensive codebase review, they found no threats to their main products, although some non-customer-facing demo and experimental projects were affected and have since been suspended until they can be updated or removed. Grafana highlights the utility of Grafana Loki for identifying potential exploitation attempts by searching for specific patterns in application logs, such as those associated with JNDI lookups and mentions of Log4j, providing users a method to gain insight into possible vulnerabilities. For further inquiries, users are encouraged to contact Grafana's security team directly.