Known Issue: Apache Log4j Vulnerability

Apache Log4j Vulnerability Flaw No Impact on Sepasoft MES Software

Information on the Apache Log4j Vulnerability flaw impact on MES Software in light of its recent discovery

https://www.wired.com/story/log4j-flaw-hacking-internet/

Sepasoft Modules use an SLF4J adaptor that uses the logging API that just uses the logging backend Ignition is providing.

Since Ignition has already asserted, that they are not impacted

https://support.inductiveautomation.com/hc/en-us/articles/4416204541709-Regarding-CVE-2021-44228-Log4j-RCE-0-day 

There is no impact to Sepasoft MES software.

Ignition includes adaptors for other common logging API's, you can use those or SLF4J directly, then those all go to the backend provided by Ignition. 


in short, we do not have a logging backend and we just use the common Ignition logging settings.

additional information from IA and Partner's Modules
https://forum.inductiveautomation.com/t/log4j-vulnerability-and-third-party-modules/54025/2