You might see that the Dropbox Community team have been busy working on some major updates to the Community itself! So, here is some info on what’s changed, what’s staying the same and what you can expect from the Dropbox Community overall.

Forum Discussion

Bigjoe910's avatar
Bigjoe910
New member | Level 2
4 years ago

Log4j Breach

After the discovery of the security breach caused by Log4j on the weekend of December 10-12, 2021. We need to know if your software is vulnerable to this security breach.

  • Walter's avatar
    Walter
    4 years ago

    Hey Bigjoe910 & leksikon - thanks for your patience while we conducted a thorough review of services and components across all Dropbox products.

    We have hardened all instances of log4j that were identified on HelloSign and Dropbox-owned platforms by applying a patch or taking other appropriate action. Like many other service providers, we continue to work with our vendors to assess impact and remediation efforts. Our systems are functioning normally and we are not aware of any active threat.

    I hope this information helps!
     

  • leksikon's avatar
    leksikon
    New member | Level 2

    My company is also asking for a status on this - is Dropbox and HelloSign affected? 

    • Walter's avatar
      Walter
      Icon for Dropbox Staff rankDropbox Staff

      Hey Bigjoe910 & leksikon - thanks for your patience while we conducted a thorough review of services and components across all Dropbox products.

      We have hardened all instances of log4j that were identified on HelloSign and Dropbox-owned platforms by applying a patch or taking other appropriate action. Like many other service providers, we continue to work with our vendors to assess impact and remediation efforts. Our systems are functioning normally and we are not aware of any active threat.

      I hope this information helps!
       

      • peteheinlein's avatar
        peteheinlein
        Explorer | Level 4

        Is there any update on if both CVE's related to Log4j are remediated or mitigated on the Dropbox platform?  The latest CVE was just added late 12/14/2021.

         

        CVE-2021-45046
        CVE-2021-44228