Forum Discussion
how to block log4j weakness on f5 ?
- Dec 16, 2021
Hi ,
according to K19026212 F5 products themselves are not vulnerable. It also describes how to use ASM or AdvWAF or iRules or NGINX App Protect in order to protect applications that are affected by the log4shell vulnerability and which are delivered via BIG-IP or NGINX.
Even if a software is using a log4j version which is affected by CVE-2021-44228, it can still be configured to be safe. As long as formatMsgNoLookups is set to true, lookups with jndi are disabled.
KR
Daniel
Hi ,
according to K19026212 F5 products themselves are not vulnerable. It also describes how to use ASM or AdvWAF or iRules or NGINX App Protect in order to protect applications that are affected by the log4shell vulnerability and which are delivered via BIG-IP or NGINX.
Even if a software is using a log4j version which is affected by CVE-2021-44228, it can still be configured to be safe. As long as formatMsgNoLookups is set to true, lookups with jndi are disabled.
KR
Daniel
- neeeewbieDec 20, 2021MVP
really thank you so much!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com