Log4j RCE (CVE-2021-4428)

We are aware of the log4j RCE (CVE-2021-4428) release today.
We would like to alleviate some of your concerns by assuring you that no components of the Syncro system are written in Java, and none of our components leverage the log4j dependency.
While you work on remediation steps, please be aware that should a vulnerability or incident of this nature occur in the future that impacts Syncro systems, one of our first action items will be to mitigate and notify our customer base accordingly.

1 Like

Hi Support, do you know if Splashtop (buit into Syncro) is subject to this vulnerability.
I have looked on the Splashtop web site and there is no announcment that I can find.

1 Like

I don’t think it would have java in splash top

1 Like

Well that’s nice to hear!

I saw on Reddit that Splashtop doesn’t use Java, so they are unaffected, but were still doing a full evaluation anyway.

1 Like

Yea, that might have been my reddit post, which was just this, in case someone didn’t know about this community/post… We should all report back here with further recommended testing strategies / outcomes yea?

1 Like

Thank-you ! It’s important to know and reassuring that Java as a whole is not used. That’s a good place to be in terms of the codebase for Syncro.

:clap:

1 Like