Head of Support
Head of Support

Log4j Zero Day Vulnerability

Log4j Zero Day Vulnerability Update – 12.14.2021 5:00 pm MST

Crownpeak is actively monitoring the Log4j2 Zero Day Vulnerability disclosed
on December 9, 2021 (CVE-2021-44228). Log4j2 affects the Apache Log4j 2
project and any systems which have deployed the library into an application.

Our operations team performed a comprehensive review of internal systems
and support applications to update or patch any affected systems. Updates
on the review results have been posted to this thread. We continue to
actively monitor the situation.

The majority of Crownpeak’s products were not affected by the Log4j2 Zero Day
Vulnerability, as they are not written in Java, or do not use the Log4j library.  The
small subset of Crownpeak’s product components which leverage the Log4j library
were affected have been identified and patched to eliminate the risk of exploit.
Specific product details are listed below.  Crownpeak will be continuing to monitor
our systems as well as third party components related to this situation closely and
report any additional updates.


DG – Privacy & Consent Management
  • No systems or components affected in the DG product set

Can't find what you are looking for?

Find Answers

Search our DG Forum to find answers to questions asked by other DG users.

Ask a Question

No luck? Ask a question. Our Product and Support teams are monitoring the Forum and typically respond within 48 hours.

Ask a Question