<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-GB">
	<id>https://wiki.eprints.org/w/index.php?action=history&amp;feed=atom&amp;title=EPrints_and_Log4Shell</id>
	<title>EPrints and Log4Shell - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.eprints.org/w/index.php?action=history&amp;feed=atom&amp;title=EPrints_and_Log4Shell"/>
	<link rel="alternate" type="text/html" href="https://wiki.eprints.org/w/index.php?title=EPrints_and_Log4Shell&amp;action=history"/>
	<updated>2026-04-21T19:03:48Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.31.8</generator>
	<entry>
		<id>https://wiki.eprints.org/w/index.php?title=EPrints_and_Log4Shell&amp;diff=13901&amp;oldid=prev</id>
		<title>Drn@ecs.soton.ac.uk: /* Potential vulnerability with Coversheets/OpenOffice Bazaar plugins */</title>
		<link rel="alternate" type="text/html" href="https://wiki.eprints.org/w/index.php?title=EPrints_and_Log4Shell&amp;diff=13901&amp;oldid=prev"/>
		<updated>2021-12-14T10:06:49Z</updated>

		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Potential vulnerability with Coversheets/OpenOffice Bazaar plugins&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revision as of 10:06, 14 December 2021&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l11&quot; &gt;Line 11:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 11:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;There is one case where Log4j will be required to support EPrints functionality and this is to provide coversheeting of PDF documents.&amp;#160; This is due to Log4j being a dependency of OpenOffice (or LibreOffice), which is used by EPrints to convert your coversheet template into a PDF, which can be attached to the original PDF.&amp;#160; &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;There is one case where Log4j will be required to support EPrints functionality and this is to provide coversheeting of PDF documents.&amp;#160; This is due to Log4j being a dependency of OpenOffice (or LibreOffice), which is used by EPrints to convert your coversheet template into a PDF, which can be attached to the original PDF.&amp;#160; &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;OpenOffice/LibreOffice will run as as a service on its own TCP port your server, so EPrints can connect to it and request the coversheet template be converted.&amp;#160; If OpenOffice/LibreOffice's TCP port is accessible beyond your server, then there is a small chance this could be exploited by Log4Shell.&amp;#160; Your organisation's firewall would &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;like &lt;/del&gt;block access to this TCP port beyond your organisation's network.&amp;#160; However, to be extra secure it is worth considering blocking remote access to this TCP port on your server's own firewall.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;OpenOffice/LibreOffice will run as as a service on its own TCP port your server, so EPrints can connect to it and request the coversheet template be converted.&amp;#160; If OpenOffice/LibreOffice's TCP port is accessible beyond your server, then there is a small chance this could be exploited by Log4Shell.&amp;#160; Your organisation's firewall would &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;likely &lt;/ins&gt;block access to this TCP port beyond your organisation's network.&amp;#160; However, to be extra secure&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;, &lt;/ins&gt;it is worth considering blocking remote access to this TCP port on your server's own firewall.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Drn@ecs.soton.ac.uk</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.eprints.org/w/index.php?title=EPrints_and_Log4Shell&amp;diff=13900&amp;oldid=prev</id>
		<title>Drn@ecs.soton.ac.uk at 23:14, 13 December 2021</title>
		<link rel="alternate" type="text/html" href="https://wiki.eprints.org/w/index.php?title=EPrints_and_Log4Shell&amp;diff=13900&amp;oldid=prev"/>
		<updated>2021-12-13T23:14:37Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revision as of 23:14, 13 December 2021&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''A basic EPrints installation is not vulnerable to [https://www.radware.com/security/threat-advisories-and-attack-reports/log4shell-critical-log4j-vulnerability/ Log4Shell] as the exploitable software ([https://logging.apache.org/log4j/2.x/ Log4j]) is not required for deployments of EPrints repository software.'''&amp;#160; &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''A basic EPrints installation is not vulnerable to [https://www.radware.com/security/threat-advisories-and-attack-reports/log4shell-critical-log4j-vulnerability/ Log4Shell] as the exploitable software ([https://logging.apache.org/log4j/2.x/ Log4j]) is not required for deployments of EPrints repository software.'''&amp;#160; &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It is possible that Log4j may be present on a server that hosts EPrints, if it has been installed for some other purpose.&amp;#160; Assuming this server is only intended for hosting EPrints repository software, in most cases (see below), it should be OK to uninstall using the operating system's package management tool:&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It is &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;still &lt;/ins&gt;possible that Log4j may be present on a server that hosts EPrints, if it has been installed for some other &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;(non-EPrints related) &lt;/ins&gt;purpose.&amp;#160; Assuming this server is only intended for hosting EPrints repository software, in most cases (see below), it should be OK to uninstall using the operating system's package management tool:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* RHEL/Fedora/CentOS: yum erase log4j&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* RHEL/Fedora/CentOS: yum erase log4j&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Debian/Ubuntu: apt purge liblog4j2-java&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Debian/Ubuntu: apt purge liblog4j2-java&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;However, [https://access.redhat.com/security/cve/cve-2021-44228 RHEL 7 and 8 do not have affected versions of Log4j], (and therefore neither do CentOS 7 and 8), so no action should required even if Log4j is installed.&amp;#160; It is less clear if versions of Log4j on Ubuntu and Debian are affected.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;However, [https://access.redhat.com/security/cve/cve-2021-44228 RHEL 7 and 8 do not have affected versions of Log4j], (and therefore neither do CentOS 7 and 8), so no action should required even if Log4j is installed.&amp;#160; It is less clear if versions of Log4j on Ubuntu and Debian are affected.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Even, if Log4j is installed on your EPrints server, it is very unlikely to be exploitable as EPrints runs on Apache HTTP server, which does not use Java, let alone Log4j.&amp;#160; Therefore, there should &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;be &lt;/del&gt;not be a means to deploy an exploit against Log4j, unless it is used by an non-EPrints related application.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Even, if Log4j is installed on your EPrints server, it is very unlikely to be exploitable as EPrints runs on Apache HTTP server, which does not use Java, let alone Log4j.&amp;#160; Therefore, there should not be a means to deploy an exploit against Log4j, unless it is used by an non-EPrints related application.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Potential vulnerability with Coversheets/OpenOffice Bazaar plugins ==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Potential vulnerability with Coversheets/OpenOffice Bazaar plugins ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Drn@ecs.soton.ac.uk</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.eprints.org/w/index.php?title=EPrints_and_Log4Shell&amp;diff=13899&amp;oldid=prev</id>
		<title>Drn@ecs.soton.ac.uk at 23:11, 13 December 2021</title>
		<link rel="alternate" type="text/html" href="https://wiki.eprints.org/w/index.php?title=EPrints_and_Log4Shell&amp;diff=13899&amp;oldid=prev"/>
		<updated>2021-12-13T23:11:26Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revision as of 23:11, 13 December 2021&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l3&quot; &gt;Line 3:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 3:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It is possible that Log4j may be present on a server that hosts EPrints, if it has been installed for some other purpose.&amp;#160; Assuming this server is only intended for hosting EPrints repository software, in most cases (see below), it should be OK to uninstall using the operating system's package management tool:&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It is possible that Log4j may be present on a server that hosts EPrints, if it has been installed for some other purpose.&amp;#160; Assuming this server is only intended for hosting EPrints repository software, in most cases (see below), it should be OK to uninstall using the operating system's package management tool:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* RHEL/Fedora/CentOS: yum erase log4j&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* RHEL/Fedora/CentOS: yum erase log4j&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Debian/Ubuntu: apt purge &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;log4j&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Debian/Ubuntu: apt purge &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;liblog4j2-java&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;However, [https://access.redhat.com/security/cve/cve-2021-44228 RHEL 7 and 8 do not have affected versions of Log4j], (and therefore neither do CentOS 7 and 8), so no action should required even if Log4j is installed.&amp;#160; It is less clear if versions of Log4j on Ubuntu and Debian are affected.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;However, [https://access.redhat.com/security/cve/cve-2021-44228 RHEL 7 and 8 do not have affected versions of Log4j], (and therefore neither do CentOS 7 and 8), so no action should required even if Log4j is installed.&amp;#160; It is less clear if versions of Log4j on Ubuntu and Debian are affected.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Drn@ecs.soton.ac.uk</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.eprints.org/w/index.php?title=EPrints_and_Log4Shell&amp;diff=13898&amp;oldid=prev</id>
		<title>Drn@ecs.soton.ac.uk: Added page about EPrints and Log4Shell</title>
		<link rel="alternate" type="text/html" href="https://wiki.eprints.org/w/index.php?title=EPrints_and_Log4Shell&amp;diff=13898&amp;oldid=prev"/>
		<updated>2021-12-13T22:43:17Z</updated>

		<summary type="html">&lt;p&gt;Added page about EPrints and Log4Shell&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;'''A basic EPrints installation is not vulnerable to [https://www.radware.com/security/threat-advisories-and-attack-reports/log4shell-critical-log4j-vulnerability/ Log4Shell] as the exploitable software ([https://logging.apache.org/log4j/2.x/ Log4j]) is not required for deployments of EPrints repository software.'''  &lt;br /&gt;
&lt;br /&gt;
It is possible that Log4j may be present on a server that hosts EPrints, if it has been installed for some other purpose.  Assuming this server is only intended for hosting EPrints repository software, in most cases (see below), it should be OK to uninstall using the operating system's package management tool:&lt;br /&gt;
* RHEL/Fedora/CentOS: yum erase log4j&lt;br /&gt;
* Debian/Ubuntu: apt purge log4j&lt;br /&gt;
However, [https://access.redhat.com/security/cve/cve-2021-44228 RHEL 7 and 8 do not have affected versions of Log4j], (and therefore neither do CentOS 7 and 8), so no action should required even if Log4j is installed.  It is less clear if versions of Log4j on Ubuntu and Debian are affected.&lt;br /&gt;
&lt;br /&gt;
Even, if Log4j is installed on your EPrints server, it is very unlikely to be exploitable as EPrints runs on Apache HTTP server, which does not use Java, let alone Log4j.  Therefore, there should be not be a means to deploy an exploit against Log4j, unless it is used by an non-EPrints related application.&lt;br /&gt;
&lt;br /&gt;
== Potential vulnerability with Coversheets/OpenOffice Bazaar plugins ==&lt;br /&gt;
There is one case where Log4j will be required to support EPrints functionality and this is to provide coversheeting of PDF documents.  This is due to Log4j being a dependency of OpenOffice (or LibreOffice), which is used by EPrints to convert your coversheet template into a PDF, which can be attached to the original PDF.  &lt;br /&gt;
&lt;br /&gt;
OpenOffice/LibreOffice will run as as a service on its own TCP port your server, so EPrints can connect to it and request the coversheet template be converted.  If OpenOffice/LibreOffice's TCP port is accessible beyond your server, then there is a small chance this could be exploited by Log4Shell.  Your organisation's firewall would like block access to this TCP port beyond your organisation's network.  However, to be extra secure it is worth considering blocking remote access to this TCP port on your server's own firewall.&lt;/div&gt;</summary>
		<author><name>Drn@ecs.soton.ac.uk</name></author>
		
	</entry>
</feed>