Number: AV21-649
Date: 22 December 2021
On 13 December 2021 Juniper published an Out of Cycle Security Advisory to address critical vulnerabilities, which may affect multiple products using the Apache Log4j logging utility.
Exploitation of these vulnerabilities could lead to remote code execution.
The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.
Out of Cycle Security Advisory (JSA11259)
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA11259&cat=SIRT_1&actp=LIST
Active Exploitation of Apache Log4j Vulnerability (AL21-019)
https://cyber.gc.ca/en/alerts/active-exploitation-apache-log4j-vulnerability