CVE-2021-44228 Vulnerability

Please direct this email to the appropriate Aspose contact for review and response.

Napersoft was made aware of the vulnerability being tracked as CVE-2021-44228. Per that CVE, the vulnerability is exposed in the “Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.”

Vendor Name : Aspose

Product: 2019-11-20 Aspose Total for Java

We ask that you please provide responses to the following questions by end of day Thursday 12/23/2021.

Acknowledge receipt of this query:

Have you taken steps to identify whether this vulnerability exists in your code base

  • Not started
  • In Progress
  • Completed

Have you engaged relevant 3rd parties that develop software as applicable

  • Yes
  • No

Confirm that you will advise Napersoft regarding the timeline to deploy patches for the compilers/programming languages as they become available:

Have you detected exploitation of this vulnerability

  • Yes
  • No

If exploitation detected, is there any potential exposure to Napersoft

  • Yes (please explain)
  • No
  • Evaluation in Progress

@sherter

We would like to share with you that Aspose Java APIs were already tested for this vulnerability. Log4J is not used in the APIs included in Aspose.Total for Java. Please note that we keep checking our APIs from time to time for such vulnerabilities and remove them if find any. That is why we always recommend using the latest available version. Please make sure that you have latest version(s) of the Aspose APIs, in case you notice any issues, please feel free to let us know.