
List of company advisories log4j
Please open Issues to include an advisory / No PRs.
https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592
This list includes all advisories of companies, even if they're just confirming that they're not using log4j at all.
| OpenMRS | https://talk.openmrs.org/t/urgent-security-advisory-2021-12-11-re-apache-log4j-2/35341 | Yes |
| N-Able | https://www.n-able.com/security-and-privacy/apache-log4j-vulnerability | Maybe |
| NetApp | https://security.netapp.com/advisory/ntap-20211210-0007/ | Yes, but nothing available yet |
| NSA Ghidra | https://github.com/NationalSecurityAgency/ghidra#warning | Yes |
| Paloalto Networks | https://security.paloaltonetworks.com/CVE-2021-44228 | No |
| PulseSecure | https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB44933/ | No |
| Red Hat | https://access.redhat.com/security/vulnerabilities/RHSB-2021-009?sc_cid=701f2000000tyBjAAI | Yes |
| SalesForce | https://help.salesforce.com/s/articleView?id=000363736&type=1 | Check later, they're currently investigating |
| SonarQube | https://community.sonarsource.com/t/sonarqube-and-the-log4j-vulnerability/54721 | Check later, they're currently investigating |
| Sonatype | https://blog.sonatype.com/a-new-0-day-log4j-vulnerability-discovered-in-the-wild | Check later, they're currently investigating |
| Sophos | https://www.sophos.com/en-us/security-advisories/sophos-sa-20211210-log4j-rce | No |
| VMware | https://www.vmware.com/security/advisories/VMSA-2021-0028.html | Yes |