What the vendor says is affected
The collected bulletin did not provide a separate affected-products list. Check the original bulletin before making an exposure decision.
What the vendor recommends
The agent will attempt to patch the lookup() method of all loaded org.apache.logging.log4j.core.lookup.JndiLookup instances to unconditionally return the string "Patched JndiLookup::lookup()".
Review the complete instructions on the vendor's siteWhat changed in later vendor updates
SecurityAlert records field-level changes from the point we begin following a bulletin. Earlier vendor changes may not have a field-by-field record.
- The vendor changed the advisory's last-updated date.
When this advisory changed
- Added to SecurityAlert
We collected the advisory from the official source.
- Published by AWS
The publication date reported by the vendor.
- Confirmed at the source
Our collector saw this advisory during a later source check.