# Log4J Vulnerability

**URL:** <https://community.apollographql.com/t/log4j-vulnerability/2214>\
**Category:** Announcements\
**Tags:** server\
**Created:** [December 12, 2021, 2:29pm UTC](https://community.apollographql.com/t/log4j-vulnerability/2214 "2021-12-12T14:29:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![marsh3232](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/marsh3232/32/1464_2.png) [@marsh3232](https://community.apollographql.com/u/marsh3232)\
**Post date:** [December 12, 2021, 2:29pm UTC](https://community.apollographql.com/t/log4j-vulnerability/2214/1 "2021-12-12T14:29:49Z")

</div>

Apollo is using log4js somewhere in it’s system. I am wondering if this is at risk of the current log4j vulernability that was recently discovered?

---

<div class="post-metadata">

**Author:** ![marsh3232](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/marsh3232/32/1464_2.png) [@marsh3232](https://community.apollographql.com/u/marsh3232)\
**Post date:** [December 13, 2021, 8:38pm UTC](https://community.apollographql.com/t/log4j-vulnerability/2214/2 "2021-12-13T20:38:54Z")

</div>

Though log4js is not vulnerable in that it is only similar in the task and name, it would be good to know from Apollo if they have any systems that are vulnerable

---

<div class="post-metadata">

**Author:** ![cpeacock](https://avatars.discourse-cdn.com/v4/letter/c/b9e5f3/32.png) [@cpeacock](https://community.apollographql.com/u/cpeacock)\
**Post date:** [December 14, 2021, 3:22pm UTC](https://community.apollographql.com/t/log4j-vulnerability/2214/3 "2021-12-14T15:22:31Z")

</div>

Hi there! On the day the vulnerability was released, we looked through both our open source packages and our cloud services and infrastructure. We found one system internally that could have had the vulnerability and patched it day of release. That system does not execute any client code directly at any time, and after doing investigation we found no evidence of any exploitation or compromise on that day or any day prior.

Those using the federation-jvm repository could enable log4j on their own, but from that end we use slf4j as a facade to log4j, and is not technically bundled with the package. The example code from that repo also uses logback-classic instead of log4j.

I’ll follow this thread if there’s any questions from anyone else!

Thanks,  
Chas Peacock, Director, Engineering

---

<div class="post-metadata">

**Author:** ![cpeacock](https://avatars.discourse-cdn.com/v4/letter/c/b9e5f3/32.png) [@cpeacock](https://community.apollographql.com/u/cpeacock)\
**Post date:** [December 15, 2021, 5:56pm UTC](https://community.apollographql.com/t/log4j-vulnerability/2214/4 "2021-12-15T17:56:22Z")

</div>

Just to follow up, we are doing the same patching mechanic with the new vulnerability around the incomplete patch today on that same system.

---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/system/32/5529_2.png) [@system](https://community.apollographql.com/u/system)\
**Post date:** [February 7, 2025, 12:08am UTC](https://community.apollographql.com/t/log4j-vulnerability/2214/5 "2025-02-07T00:08:15Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/system/32/5529_2.png) [@system](https://community.apollographql.com/u/system)\
**Post date:** [February 10, 2025, 8:41pm UTC](https://community.apollographql.com/t/log4j-vulnerability/2214/6 "2025-02-10T20:41:21Z")

</div>


