# Log4j Vulnerability

**URL:** <https://community.open-emr.org/t/log4j-vulnerability/17558>\
**Category:** Security\
**Tags:** question\
**Created:** [December 15, 2021, 9:33am UTC](https://community.open-emr.org/t/log4j-vulnerability/17558 "2021-12-15T09:33:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hitechelp](https://community.open-emr.org/user_avatar/community.open-emr.org/hitechelp/32/11911_2.png) [@hitechelp](https://community.open-emr.org/u/hitechelp)\
**Post date:** [December 15, 2021, 9:33am UTC](https://community.open-emr.org/t/log4j-vulnerability/17558/1 "2021-12-15T09:33:32Z")

</div>

Is OpenEMR using Log4j anywhere?

---

<div class="post-metadata">

**Author:** ![adunsulag](https://community.open-emr.org/user_avatar/community.open-emr.org/adunsulag/32/12606_2.png) [@adunsulag](https://community.open-emr.org/u/adunsulag)\
**Post date:** [December 15, 2021, 12:42pm UTC](https://community.open-emr.org/t/log4j-vulnerability/17558/2 "2021-12-15T12:42:00Z")

</div>

As far as I know nothing in the OpenEMR codebase uses Log4j. For those hosting in the cloud on Amazon, several of the AWS services had vulnerabilities and Amazon is in the process of fixing those. S3 has been patched and the database services for Aurora and RDS are in the process of being patched.

I’ve been following this handy reference to check what software I use against any posted vulnerabilities. [log4shell/software at main · NCSC-NL/log4shell · GitHub](https://github.com/NCSC-NL/log4shell/tree/main/software)

---

<div class="post-metadata">

**Author:** ![sophisticated\_acquis](https://community.open-emr.org/user_avatar/community.open-emr.org/sophisticated_acquis/32/15773_2.png) [@sophisticated\_acquis](https://community.open-emr.org/u/sophisticated_acquis)\
**Post date:** [December 15, 2021, 12:57pm UTC](https://community.open-emr.org/t/log4j-vulnerability/17558/3 "2021-12-15T12:57:44Z")

</div>

Thank you for sharing this!
