# Node red and log4j vulnerability

**URL:** <https://discourse.nodered.org/t/node-red-and-log4j-vulnerability/55191>\
**Category:** Core Development\
**Tags:** security\
**Created:** [14 December 2021 16:28 UTC](https://discourse.nodered.org/t/node-red-and-log4j-vulnerability/55191 "2021-12-14T16:28:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![TKFCE](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/tkfce/32/52656_2.png) [@TKFCE](https://discourse.nodered.org/u/TKFCE)\
**Post date:** [14 December 2021 16:28 UTC](https://discourse.nodered.org/t/node-red-and-log4j-vulnerability/55191/1 "2021-12-14T16:28:48Z")

</div>

Hi Treasured node-red community.

Is there any indication from Devs if node-red might be affected by the log4j vulnerability?  
[Tech Solvency: The Story So Far: CVE-2021-44228 (Log4Shell log4j vulnerability).](https://www.techsolvency.com/story-so-far/cve-2021-44228-log4j-log4shell/)

Naturally we already avoid to expose any Node-RED page to the public internet.  
However it pays to be safe. We have already had phishing attempts and door knocks related to this exploit at our organisation so we must take it seriously.

---

<div class="post-metadata">

**Author:** ![cymplecy](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/cymplecy/32/2773_2.png) [@cymplecy](https://discourse.nodered.org/u/cymplecy)\
**Post date:** [14 December 2021 16:35 UTC](https://discourse.nodered.org/t/node-red-and-log4j-vulnerability/55191/2 "2021-12-14T16:35:44Z")

</div>

> [@Log4J vulnerability](https://discourse.nodered.org/t/log4j-vulnerability/55181/2):
>
> Log4J is a Java Library, not a JavaScript library It will not be used by any node-red apps

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [14 December 2021 17:47 UTC](https://discourse.nodered.org/t/node-red-and-log4j-vulnerability/55191/3 "2021-12-14T17:47:49Z")

</div>

As a member of a Java team (during my daily job), I can confirm this. If I hear the word "log4j" once more today, then I am going to bang my head against the wall 😉

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [14 December 2021 21:36 UTC](https://discourse.nodered.org/t/node-red-and-log4j-vulnerability/55191/4 "2021-12-14T21:36:59Z")

</div>

> [@BartButenaers](#):
>
> As a member of a Java team (during my daily job)

I'm so sorry for your loss! ☹

> [@BartButenaers](#):
>
> If I hear the word "log4j" once more today, then I am going to bang my head against the wall

Ah, well perhaps be thankful that you don't have it buried away in critical services like we seem to have.

---

<div class="post-metadata">

**Author:** ![TKFCE](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/tkfce/32/52656_2.png) [@TKFCE](https://discourse.nodered.org/u/TKFCE)\
**Post date:** [15 December 2021 10:50 UTC](https://discourse.nodered.org/t/node-red-and-log4j-vulnerability/55191/5 "2021-12-15T10:50:44Z")

</div>

Thanks for your time with this everyone, appreciate it.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [15 December 2021 11:08 UTC](https://discourse.nodered.org/t/node-red-and-log4j-vulnerability/55191/6 "2021-12-15T11:08:02Z")

</div>

This is a useful link regarding what is impacted:

[https://www.techsolvency.com/story-so-far/cve-2021-44228-log4j-log4shell/#affected-products](https://www.techsolvency.com/story-so-far/cve-2021-44228-log4j-log4shell/#affected-products)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [29 December 2021 11:08 UTC](https://discourse.nodered.org/t/node-red-and-log4j-vulnerability/55191/7 "2021-12-29T11:08:27Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
