<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exact Log4J version on Panorama 9.0.15 in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/exact-log4j-version-on-panorama-9-0-15/m-p/459811#M664</link>
    <description>&lt;H4&gt;Q. How was Log4j fixed in Panorama?&lt;/H4&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;In fixed versions of PAN-OS for Panorama, the included Elasticsearch package was remediated through the deletion of the vulnerable Log4j JndiLookup class file. This solution is provided by Elasticsearch announcement (ESA-2021-31) and the Log4j Security Vulnerabilities Page as a complete remediation option for CVE-2021-44228 and CVE-2021-45046. Panorama appliances are not impacted by CVE-2021-45105 and require no specific fix.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
    <pubDate>Thu, 20 Jan 2022 14:43:16 GMT</pubDate>
    <dc:creator>PerryPapanier</dc:creator>
    <dc:date>2022-01-20T14:43:16Z</dc:date>
    <item>
      <title>Exact Log4J version on Panorama 9.0.15</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/exact-log4j-version-on-panorama-9-0-15/m-p/454664#M585</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just upgraded our Panorama servers to 9.0.15, but our SOC team is asking to know the exact log4j version included in this hotfix release, because they want all appliances to be upgraded to log4j 2.16.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;According to this page (&lt;A href="https://docs.paloaltonetworks.com/oss-listings/panorama-oss-listings/panorama-9-0-open-source-software-oss-listing.html#idcddd66f0-c26a-43e5-b143-e777cd4f4ca4" target="_blank"&gt;https://docs.paloaltonetworks.com/oss-listings/panorama-oss-listings/panorama-9-0-open-source-software-oss-listing.html#idcddd66f0-c26a-43e5-b143-e777cd4f4ca4&lt;/A&gt;), Panorama 9.0 includes log4j version 2.9.1, so I think that they have made some mitigations/corrections to the code or the configuration to fix the vulnerability, rather than upgrading log4j to a newer version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anybody know more on this?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 10:59:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/exact-log4j-version-on-panorama-9-0-15/m-p/454664#M585</guid>
      <dc:creator>grenzi</dc:creator>
      <dc:date>2021-12-21T10:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Exact Log4J version on Panorama 9.0.15</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/exact-log4j-version-on-panorama-9-0-15/m-p/459811#M664</link>
      <description>&lt;H4&gt;Q. How was Log4j fixed in Panorama?&lt;/H4&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;In fixed versions of PAN-OS for Panorama, the included Elasticsearch package was remediated through the deletion of the vulnerable Log4j JndiLookup class file. This solution is provided by Elasticsearch announcement (ESA-2021-31) and the Log4j Security Vulnerabilities Page as a complete remediation option for CVE-2021-44228 and CVE-2021-45046. Panorama appliances are not impacted by CVE-2021-45105 and require no specific fix.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Thu, 20 Jan 2022 14:43:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/exact-log4j-version-on-panorama-9-0-15/m-p/459811#M664</guid>
      <dc:creator>PerryPapanier</dc:creator>
      <dc:date>2022-01-20T14:43:16Z</dc:date>
    </item>
  </channel>
</rss>

