Log4Shell: RCE 0-day exploit - CVE-2021-44228
Incident Report for Digital Pacific
Resolved
This incident has been resolved.
Posted Dec 24, 2021 - 10:54 AEDT
Monitoring
cPanel has released an update which fixes the Java Log4j Remote Code Execution Vulnerability (CVE-2021-44228).

We have confirmed this update has been applied to all of our shared & reseller hosting servers.

This update will have also applied to our Managed cPanel clients during the nightly cPanel updates.

We are continuing to monitoring all shared, reseller and managed services in the usual manner.
Posted Dec 15, 2021 - 15:50 AEDT
Identified
We are investigating the impact of the reported Java Log4j Remote Code Execution Vulnerability (CVE-2021-44228) on our managed clients and infrastructure.

Packages have already been automatically updated with the upstream patches when available from vendors.

When updates are not available from upstream vendors, we are investigating the next best course of action to ensure all systems and services remain secure.
Posted Dec 13, 2021 - 12:53 AEDT