logo

MarketONE
Developer

MarketONE

Apache Log4j2 Security Notice

Incident Report for MarketONE

Resolved

A zero-day critical vulnerability of Apache Log4j2 was announced recently (CVE-2021-44228: https://nvd.nist.gov/vuln/detail/CVE-2021-44228), enabling remote attackers to control an affected system.

Please be assured that Vindicia completed the analysis when the exploit was first announced. We have determined that this does not impact our existing services.

Specifically For Vindicia MarketONE:

- Subscribe (Subscribe API): Does not use log4j2 libraries.

- Bundle (Partner API): Does not use log4j2 libraries.

- Connect (User API): Uses log4j2. However, we have confirmed that The exploit will not impact Connect based on our configuration. As an added precaution, we will be applying additional configuration updates to the Connect APIs.

If you have any questions, please post a ticket to https://clientsupport.vindicia.com or contact support@vindicia.com.
Posted Dec 13, 2021 - 17:37 UTC
This incident affected: API and Portal.