Select to view content in your preferred language

How to handle log4j flagged in ArcGIS Portal and Pro directory?

305
2
Jump to solution
10-23-2024 10:46 PM
Yogesh_Chavan
Frequent Contributor

Hello,

Can someone confirm if the below flagged directories with log4j be considered unsafe? We are using ArcGIS Enterprise 11.3 and these components were flagged on the ArcGIS Portal machine.


Directory of C:\Program Files\ArcGIS\Portal\framework\runtime\ds\framework\lib 

log4j-1.2-api.jar


Directory of C:\Program Files\ArcGIS\Portal\framework\runtime\ds\framework\runtime\opensearch\plugins\repository-gcs

log4j-1.2-api-2.20.0.jar


Directory of C:\Program Files\ArcGIS\Portal\framework\runtime\ds\framework\runtime\opensearch\plugins\repository-s3

log4j-1.2-api-2.20.0.jar
               

Directory of C:\Program Files\ArcGIS\Portal\framework\runtime\tomcat\lib

log4j-1.2-api-2.22.1.jar
           

Directory of C:\Program Files\ArcGIS\Pro\bin\Python\envs\arcgispro-py3\Lib\site-packages\saspy\java\iomclient

 log4j-1.2-api-2.19.0.jar          

Directory of C:\Program Files\ArcGIS\Pro\java\runtime\spark\jars

 log4j-1.2-api-2.20.0.jar
          

 

0 Kudos
1 Solution

Accepted Solutions
ChrisUnderwood
Esri Contributor

Hello @Yogesh_Chavan , you don't mention what security scanner you used to generate this list. False positives can be a problem with many scanners. Check whether you are using one of the scanners listed in the Security Scanner False Positives section below.

https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/arcgis-software-and-cve-2...

 

View solution in original post

2 Replies
ChrisUnderwood
Esri Contributor

Hello @Yogesh_Chavan , you don't mention what security scanner you used to generate this list. False positives can be a problem with many scanners. Check whether you are using one of the scanners listed in the Security Scanner False Positives section below.

https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/arcgis-software-and-cve-2...

 

Yogesh_Chavan
Frequent Contributor

Thank you for the details @ChrisUnderwood, I can check these details with the IT team.

0 Kudos