# UPDATE: FIX RELEASED FOR BOTH CVE-2021-44228 or CVE-2021-45046/ log4j2

**URL:** <https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298>\
**Category:** Wowza Streaming Engine\
**Created:** [December 10, 2021, 2:25pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298 "2021-12-10T14:25:45Z")\
**Posts on this page:** 15\
**Page:** 2

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [December 15, 2021, 6:50pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/21 "2021-12-15T18:50:22Z")

</div>

Correct! In the works right now and I will once again post when I have the release details for next version of Streaming Engine. Great question to ask, thanks @Bernhard_Schmidt

---

<div class="post-metadata">

**Author:** ![Piero\_Ragazzini](https://avatars.discourse-cdn.com/v4/letter/p/5f8ce5/32.png) [@Piero\_Ragazzini](https://community.wowza.com/u/Piero_Ragazzini)\
**Post date:** [December 15, 2021, 11:15pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/22 "2021-12-15T23:15:31Z")

</div>

Hi, the fix generates the following errors.

It’s normal?  
where am i wrong?

thx!

* * *

gestione@WowzaStreaming:/usr/local/WowzaStreamingEngine/updates/updatelog4j$ sudo ./updatelog4j.sh  
Verifying running as administrative user  
updating /usr/local/WowzaStreamingEngine/lib  
deleteing /usr/local/WowzaStreamingEngine/lib/log4j-api-2.16.0.jar  
copying ./log4j-api-2.16.0.jar to /usr/local/WowzaStreamingEngine/lib/  
deleteing /usr/local/WowzaStreamingEngine/lib/log4j-core-2.16.0.jar  
copying ./log4j-core-2.16.0.jar to /usr/local/WowzaStreamingEngine/lib/  
updating /usr/local/WowzaStreamingEngine/manager/lib/WMSManager.war  
**./updatelog4j.sh: riga 63: zip: comando non trovato**  
**./updatelog4j.sh: riga 64: zip: comando non trovato**  
**./updatelog4j.sh: riga 71: zip: comando non trovato**  
**./updatelog4j.sh: riga 72: zip: comando non trovato**  
Update Complete. Please restart services  
gestione@WowzaStreaming:/usr/local/WowzaStreamingEngine/updates/updatelog4j$

---

<div class="post-metadata">

**Author:** ![Charles\_Gaefke1](https://avatars.discourse-cdn.com/v4/letter/c/6de8d8/32.png) [@Charles\_Gaefke1](https://community.wowza.com/u/Charles_Gaefke1)\
**Post date:** [December 16, 2021, 2:04am UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/23 "2021-12-16T02:04:36Z")

</div>

I too saw that, in english, on our linux wowza server.

---

<div class="post-metadata">

**Author:** ![Yuichi\_OHKAWA](https://avatars.discourse-cdn.com/v4/letter/y/9dc877/32.png) [@Yuichi\_OHKAWA](https://community.wowza.com/u/Yuichi_OHKAWA)\
**Post date:** [December 16, 2021, 3:37am UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/24 "2021-12-16T03:37:12Z")

</div>

Hi, @Piero_Ragazzini  
I also had the same errors.  
If zip command was not installed, I think that updatelog4j.sh doedn’t work properly.  
I installed zip into OS, then executed updatelog4j.sh again.

---

<div class="post-metadata">

**Author:** ![Piero\_Ragazzini](https://avatars.discourse-cdn.com/v4/letter/p/5f8ce5/32.png) [@Piero\_Ragazzini](https://community.wowza.com/u/Piero_Ragazzini)\
**Post date:** [December 16, 2021, 12:53pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/25 "2021-12-16T12:53:26Z")

</div>

solved thanks to your advice! thank you

---

<div class="post-metadata">

**Author:** ![Pedro\_Costa](https://avatars.discourse-cdn.com/v4/letter/p/ba9def/32.png) [@Pedro\_Costa](https://community.wowza.com/u/Pedro_Costa)\
**Post date:** [December 16, 2021, 3:53pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/26 "2021-12-16T15:53:05Z")

</div>

are you investigating earlier versions of log4j 1.X and vulnerability CVE-2021-4104 ? thank you

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [December 16, 2021, 4:33pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/27 "2021-12-16T16:33:05Z")

</div>

Thank you for posting about the zip command and we did get this updated as well!

**I’m trying to keep all the updates in this thread in one place for “accepted solution” so let me add this new update to the green checkmark solution post.**

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [December 16, 2021, 4:34pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/28 "2021-12-16T16:34:00Z")

</div>

No we are nor @Pedro_Costa

Unless the customer has changed the default settings of the JMSAppender (which we do not even use), we are not exposed to this CVE. If you have concerns, please update to 4.8.8.01 or higher.

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [December 16, 2021, 4:41pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/29 "2021-12-16T16:41:05Z")

</div>

Please send a support ticket for the engineers to review @Piero_Ragazzini . Not sure if it’s wrong or something in your server environment, but technical support can help you resolve it.

---

<div class="post-metadata">

**Author:** ![Charles\_Gaefke1](https://avatars.discourse-cdn.com/v4/letter/c/6de8d8/32.png) [@Charles\_Gaefke1](https://community.wowza.com/u/Charles_Gaefke1)\
**Post date:** [December 16, 2021, 5:11pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/30 "2021-12-16T17:11:20Z")

</div>

Installing zip with ‘apt install zip’ took care of those errors for me that Piero\_Ragazzini was referring to.

---

<div class="post-metadata">

**Author:** ![Piero\_Ragazzini](https://avatars.discourse-cdn.com/v4/letter/p/5f8ce5/32.png) [@Piero\_Ragazzini](https://community.wowza.com/u/Piero_Ragazzini)\
**Post date:** [December 16, 2021, 5:18pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/31 "2021-12-16T17:18:58Z")

</div>

I did it but @Yuichi_OHKAWA gave me the correct answer.  
thx

---

<div class="post-metadata">

**Author:** ![Piero\_Ragazzini](https://avatars.discourse-cdn.com/v4/letter/p/5f8ce5/32.png) [@Piero\_Ragazzini](https://community.wowza.com/u/Piero_Ragazzini)\
**Post date:** [December 18, 2021, 6:39pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/32 "2021-12-18T18:39:16Z")

</div>

## Important: Security Vulnerability CVE-2021-45105

The Log4j team has been made aware of a security vulnerability, CVE-2021-45105, that has been addressed in Log4j 2.17.0 for Java 8 and up.

Summary: Apache Log4j2 does not always protect from infinite recursion in lookup evaluation.

[https://logging.apache.org/log4j/2.x/](https://logging.apache.org/log4j/2.x/)

---

<div class="post-metadata">

**Author:** ![Marcel\_Linke](https://avatars.discourse-cdn.com/v4/letter/m/858c86/32.png) [@Marcel\_Linke](https://community.wowza.com/u/Marcel_Linke)\
**Post date:** [December 19, 2021, 3:24pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/33 "2021-12-19T15:24:57Z")

</div>

It would also be nice if the Wowza Team do update the log4j\*.jar Files in the Updater (and Installer!?) File for Wowza 4.8.16+1. At the Moment we have log4j Version 2.13.3 in the /lib Folders.

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [December 20, 2021, 5:15pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/34 "2021-12-20T17:15:25Z")

</div>

**Please continue to check my post above for updates in the post with a green checkmark.**

As far as updaters and installers @Marcel_Linke Also that updater with 2.16 was released last week so you must have missed my update. Keep checking our doc too that I posted. As the information has changed over the weekend from Apache, we have had to release a new updater today (Monday) to include Apache 2.17. This is a dynamic situation with Apache and we are updating accordingly as info comes in.

Please keep yourself informed by following my main post here.

**I JUST POSTED A NEW UPDATE: MONDAY 12.20**

---

<div class="post-metadata">

**Author:** ![James\_Broberg](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/james_broberg/32/1022_2.png) [@James\_Broberg](https://community.wowza.com/u/James_Broberg)\
**Post date:** [December 30, 2021, 10:40pm UTC](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298/35 "2021-12-30T22:40:00Z")

</div>

CVE-2021-44832 and 2.17.1 are now released. Does this impact Wowza as it’s currently configured out of the box and/or with the suggested start changes to Manager and Engine?

[Previous page](https://community.wowza.com/t/update-fix-released-for-both-cve-2021-44228-or-cve-2021-45046-log4j2/94298.md?page=1)
