Zabbix (Multiple Products)


Vendor Data
Community Data Not Vulnerable

Vendor Resources

Resource Link
Zabbix Log4j https://blog.zabbix.com/zabbix-not-affected-by-the-log4j-exploit/17873/

Community Resources

Resource Link
source https://blog.zabbix.com/zabbix-not-affected-by-the-log4j-exploit/17873/

Community Notes

Source Note
NCSC-NL CVE-2021-4104: Not vuln ; CVE-2021-44228: Not vuln ; CVE-2021-45046: Not vuln ; CVE-2021-45105: Not vuln
NCSC-NL Zabbix is aware of this vulnerability, has completed verification, and can conclude that the only product where we use Java is Zabbix Java Gateway, which does not utilize the log4j library, thereby is not impacted by this vulnerability.

Sources

Date Attribution Description
2021-12-27 15:29:04 NCSC-NL Updated communityNotVulnerable. Updated community note. Updated community link source. Updated community note.
2021-12-30 21:31:50 CISAGov Updated vendor link Zabbix Log4j.