Box and Apache Log4j
Do you know if Box Drive, Sync or Tools are using Apache Log4j utility?
There is a new vulnerability, CVE-2021-44228, that affects Apache Log4j2.
-
Official comment
Hi Everyone,
A quick update regarding this issue:
"On Dec 9th, 2021, security researchers published a report of a high risk "zero day" vulnerability (CVE-2021-44228) affecting a common software package (Apache Log4J). Box's security and engineering teams immediately began investigating the report and assessing our own systems for impact. At this time, there is no evidence that the Box Service and related systems were successfully exploited.
While we determined that there were a few vulnerable versions of the package within the Box Service and Infrastructure, Box generally uses a version that wasn't vulnerable. The limited occurrence combined with Box's pre-existing layers of defensive measures maintained for our extensive compliance certifications and industry best practices, prevented the exploitation of any vulnerable versions of Log4J.
While the instances of the vulnerability were not exploitable and limited, we quickly started and continue to patch services that contained the vulnerable package. As part of our response, we are taking the following additional steps:- Extensively reviewed all patched services for malicious behavior prior to patch application and continue to verify our security posture of the patched environment with our typical security exercises, including our Bug Bounty program, external and internal penetration testings, red team activities, etc.
- Updated all our security devices with relevant Log4j signatures to detect and contain malicious activity related to this exploit where applicable.
- Continuously monitor and analyze logs after patching is complete.
- Keeping in touch with industry peers to collect intelligence and mitigation techniques to apply to our environment as needed.
- Additional internal patching will continue over the next few days as we continue to scan extensively our environment to discover any vulnerable version of the package.
- We are also in contact with our vendors as a part of our rigorous third-party risk management process to further assess any potential vulnerabilities or impact.
Protecting our customers' data is our top priority and at this time there is no action that you need to take in regard to the Box platform. If we identify any malicious activity that might impact your data, we will immediately notify and work with your teams. For any specific concerns, please reach out to support.box.com or visit the Box Trust Center to learn more about our approach to security, privacy and compliance."Thanks again for your inquiries and we appreciate your partnership in this matter.Comment actions -
I totally agree... Would be nice to know if Box can attest that they have implemented the "Apache released Log4j version 2.15.0 security update to address this vulnerability." https://www.cisa.gov/uscert/apache-log4j-vulnerability-guidance
-
Hi Everyone,
Welcome to the Box Community and thank you for your posts!
We have been actively investigating the impact of Log4J on Box, and we have found no evidence of successful exploitation. We will share additional details soon. We're taking this review seriously and our teams are working to provide updates as we have them.
You may also find Box's official statement regarding this matter on this blog post.
Many thanks for your participation in the forum and let us know how else we can help!
Post is closed for comments.
Comments
19 comments