# Log4j vulnerability in Yugabyte

**URL:** <https://forum.yugabyte.com/t/log4j-vulnerability-in-yugabyte/1379>\
**Category:** General\
**Created:** [January 5, 2022, 9:09pm UTC](https://forum.yugabyte.com/t/log4j-vulnerability-in-yugabyte/1379 "2022-01-05T21:09:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ars1206](https://avatars.discourse-cdn.com/v4/letter/a/a587f6/32.png) [@ars1206](https://forum.yugabyte.com/u/ars1206)\
**Post date:** [January 5, 2022, 9:09pm UTC](https://forum.yugabyte.com/t/log4j-vulnerability-in-yugabyte/1379/1 "2022-01-05T21:09:42Z")

</div>

Couple of weeks back Log4j security vulnerability was discovered. Does Yugabyte have Log4j vulnerability? If yes, any plan to fix it and release the patch?

---

<div class="post-metadata">

**Author:** ![Marko\_Rajcevic](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.yugabyte.com/marko_rajcevic/32/401_2.png) [@Marko\_Rajcevic](https://forum.yugabyte.com/u/Marko_Rajcevic)\
**Post date:** [January 5, 2022, 9:48pm UTC](https://forum.yugabyte.com/t/log4j-vulnerability-in-yugabyte/1379/2 "2022-01-05T21:48:19Z")

</div>

Hi @ars1206 ! Thanks for reaching out. Below is Yugabyte’s official statement regarding the Log4j vulnerability:

" **Yugabyte is aware of the recently disclosed Apache Log4j2 vulnerability (CVE-2021-44228). We have assessed the potential impact of the vulnerability on Yugabyte products and services and have confirmed that Yugabyte products and services are not affected. The Apache Log4j2 utility is a commonly used component for logging requests, but it is not used within Yugabyte products and services. We appreciate your trust and we continue to make your success our top priority.**"
