CVE-2021-44228 Is Capture One Affected?
Is CaptureOne affected by the current Log4j security vulnerability?
https://nvd.nist.gov/vuln/detail/CVE-2021-44228
-
To me C1 looks to be a .NET application, not Java. Since Log4j is for Java apps, I'd say no.
Also the credits.txt file, which mentions the different libraries and toolkits used in C1 does not contain any reference to Log4J.1 -
hopefully there will come an official statement...
0 -
I would not hold my breath on the forums. If you need an official statement for your company's risk compliance I'd submit a request (top right corner). Hopefully they'll answer you via that route.
But again, the C1 app is not written in Java and I found no trace of log4j being used. IT is my job. I understand you won't take an internet stranger for his word though.0
投稿コメントは受け付けていません。
コメント
3件のコメント