Arduino Hardware Support Package Log4j CVE-2021-44228 Vulnerability

11 ビュー (過去 30 日間)
James Cox
James Cox 2021 年 12 月 16 日
コメント済み: Volker 2022 年 3 月 29 日
I see in the Mathworks Trust Center you have posted a response to CVE-2021-44228 Log4j vulnerability. A scan of our Matlab installation reveals Log4J version 2.12.0 in folder:
\MATLAB\SupportPackages\R2021a\aIDE\lib
I believe this is related to the installed Arduino hardware support package. This looks like the same file version shipped with the Arduino IDE version 1.8.16.
Does the Trust Center statement cover this and similar Arduino support packages?

回答 (1 件)

Sebastian
Sebastian 2021 年 12 月 21 日
We are aware of this vulnerability. The issue arises from use of the third-party Arduino toolchain and IDE that is required by our support package.
We are intending to update Arduino IDE that our Support Package uses as soon as feasible
  3 件のコメント
Nick Moore
Nick Moore 2022 年 1 月 6 日
When should we expect an update to be released? Arduino removed log4j on 12-21.
Volker
Volker 2022 年 3 月 29 日
What is the staus of that fix? I cannot find any answer that it was fixed by now

サインインしてコメントする。

カテゴリ

Help Center および File ExchangeArduino Hardware についてさらに検索

製品


リリース

R2021a

Community Treasure Hunt

Find the treasures in MATLAB Central and discover how the community can help you!

Start Hunting!

Translated by