{"id":1332,"date":"2021-12-14T12:47:17","date_gmt":"2021-12-14T11:47:17","guid":{"rendered":"https:\/\/blog.church.tools\/en\/?p=1332"},"modified":"2021-12-14T12:47:17","modified_gmt":"2021-12-14T11:47:17","slug":"churchtools-is-not-affected-log4j-vulnerability","status":"publish","type":"post","link":"https:\/\/blog.church.tools\/en\/churchtools-is-not-affected-log4j-vulnerability\/","title":{"rendered":"ChurchTools is not affected: log4j vulnerability"},"content":{"rendered":"\n<p>The Internet has been <a href=\"https:\/\/www.wired.com\/story\/log4j-flaw-hacking-internet\/\" target=\"_blank\" rel=\"noreferrer noopener\">full of reports<\/a> about a critical security vulnerability in recent days. A security vulnerability has been discovered in a software package called log4j, which even the German <a href=\"https:\/\/www.bsi.bund.de\/SharedDocs\/Cybersicherheitswarnungen\/DE\/2021\/2021-549032-10F2.html\" target=\"_blank\" rel=\"noreferrer noopener\">BSI<\/a> (Federal Office for IT Security) describes as a &#8220;critical threat situation&#8221; and declares a red alert level for it.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blog.church.tools\/wp-content\/uploads\/2021\/12\/fly-d-zAhAUSdRLJ8-unsplash-e1639471862540-1024x335.jpg\" alt=\"Foto eines offenen Schlosses auf losen Tastaturbuchstaben\" class=\"wp-image-2327\" \/><figcaption>Photo by <a href=\"https:\/\/unsplash.com\/@flyd2069?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText\">FLY:D<\/a> on <a href=\"https:\/\/unsplash.com\/s\/photos\/hacking?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText\">Unsplash<\/a>\n  <\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Is ChurchTools (software) affected?<\/h2>\n\n\n\n<p>No. The mentioned software package is not used by ChurchTools, because it is a completely different coding language. Thus, there is not and never was a security risk for our customers or their data.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Measures were nevertheless taken<\/h2>\n\n\n\n<p>ChurchTools as a company nevertheless uses internally Java-based services for operation, which use log4j as a dependency. We shut down these services as a precaution after we became aware of the vulnerability (this does not affect our customers!) and carefully checked all our services. We were unable to detect any abuse of this security vulnerability. In addition, these services are not accessible from the Internet, but are only available to ChurchTools employees (keyword: VPN).<\/p>\n\n\n\n<p>IT security is very important to us and we are glad that we and our customers are not affected by this gap. The security of customer data is of great concern to us!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Internet has been full of reports about a critical security vulnerability in recent days. A security vulnerability has been discovered in a software package called log4j, which even the German BSI (Federal Office for IT Security) describes as a<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1332","post","type-post","status-publish","format-standard","hentry","category-changelog"],"_links":{"self":[{"href":"https:\/\/blog.church.tools\/en\/wp-json\/wp\/v2\/posts\/1332","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.church.tools\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.church.tools\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.church.tools\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.church.tools\/en\/wp-json\/wp\/v2\/comments?post=1332"}],"version-history":[{"count":4,"href":"https:\/\/blog.church.tools\/en\/wp-json\/wp\/v2\/posts\/1332\/revisions"}],"predecessor-version":[{"id":1340,"href":"https:\/\/blog.church.tools\/en\/wp-json\/wp\/v2\/posts\/1332\/revisions\/1340"}],"wp:attachment":[{"href":"https:\/\/blog.church.tools\/en\/wp-json\/wp\/v2\/media?parent=1332"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.church.tools\/en\/wp-json\/wp\/v2\/categories?post=1332"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.church.tools\/en\/wp-json\/wp\/v2\/tags?post=1332"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}