Dear customers,
We have identified Genero Report Writer (GRW/GRE) as using the Java library log4j; however, it uses version 1.2.17 which does not fall within the effected version range (2.0beta9 -> 2.14.1).
If you read the page
https://logging.apache.org/log4j/2.x/security.html, you will see in the mitigation section that "Log4j 1.x mitigation: Log4j 1.x is not impacted by this vulnerability."
Some of you reported that the log4j version 1.2.17 has also a moderate vulnerability CVE-2019-17571 about a SocketServer that accepts serialized log events and deserializes them without verifying whether the objects are allowed or not.
GRE doesn't use SocketServer; therefore, GRE 3.10, 3.20, and 4.00 can be used, as they are not affected by this vulnerability.
As a result, there is no immediate need for Four Js to update log4j to the latest log4j version.
Four Js is evaluating the updates to the latest log4j version, to analyze the impact of the update on our products.
We will keep you informed of the evaluation.
Thank you,
Four Js Development Tools