Do you know if Box Drive, Sync or Tools are using Apache Log4j utility?
There is a new vulnerability, CVE-2021-44228, that affects Apache Log4j2.
Do you know if Box Drive, Sync or Tools are using Apache Log4j utility?
There is a new vulnerability, CVE-2021-44228, that affects Apache Log4j2.
I am also looking for an official response from Box on this vulnerability.
Is the Box platform affected by CVE-2021-44228?
We are also looking for confirmation and an official response.
Is the Box platform affected by CVE-2021-44228?
We are also looking for confirmation and an official response.
Is the Box platform affected by CVE-2021-44228?
I am also interested in a response from Box.com, we need to confirm that Box services are NOT vulnerable to the Log4j vulnerability (log4shell).
We are also looking for confirmation and an official response.
Is the Box platform affected by CVE-2021-44228?
Hello, Box needs to come out with an official statement regarding the log4j vulnerability. Most major vendors have been very quick to respond to this, and I have not seen anything from Box yet. Is Box affected by this vulnerability?
Agree to the above statement.
Agree BOX need to make a statement on this.
I totally agree... Would be nice to know if Box can attest that they have implemented the "Apache released Log4j version 2.15.0 security update to address this vulnerability." https://www.cisa.gov/uscert/apache-log4j-vulnerability-guidance
Will BOX respond so that we know whether we are impacted the Apache log4j vulnerability CVE-2021-44228 please?
We to are looking for an official response from Box on this as it's part of our security review. Has anyone seen or know of an official response to this yet, as I can't seem to find one.
Hi Everyone,
Welcome to the Box Community and thank you for your posts!
We have been actively investigating the impact of Log4J on Box, and we have found no evidence of successful exploitation. We will share additional details soon. We're taking this review seriously and our teams are working to provide updates as we have them.
You may also find Box's official statement regarding this matter on this blog post.
Many thanks for your participation in the forum and let us know how else we can help!
Would also like update on this and link that was just posted I get a 404.
Hi Charles,
I've fixed the link for you, can you try accessing it again.
Per our Security Scans, it does not seem the regular Box Drive application is vulnerable. However the Box DICOM Proxy seems to be reliant on log4j.
Will Box be responding to this comment of 15 days ago, regarding the Box DICOM Proxy seems to be reliant on log4j ?
Every other vendor I work with has issued a pretty detailed list of whether their products use Log4j and if it does where they are in patching or monitoring. Not sure how much longer Box's thin statement will be acceptable to clients.
Hi Everyone,
A quick update regarding this issue:
Any update on this? I need confirmation if Box Drive is affected by log4j.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.