log4j vulnerability if we use containers on TrueNAS Scale?

JoeAtWork

Contributor
Joined
Aug 20, 2018
Messages
165
Hi All,

Are we protected from the log4j2 kooties if we use the containers with Scale?

Thanks,
Joe
 

Kris Moore

SVP of Engineering
Administrator
Moderator
iXsystems
Joined
Nov 12, 2015
Messages
1,471
Yes and no. You probably still want to make sure your containers are patched and clean. If a container gets compromised, the data within could be accessed, and the files shared with it via a host-volume. It does provide a layer of protection against something running wild on the host, but you still be better off without running a compromised container in the first place.
 

truecharts

Guru
Joined
Aug 19, 2021
Messages
788
From our side: We do provide automated security scans for all containers we use for our Apps, you should be able to find out if any of our Apps still have log4j related CVE's open just by looking at their documentation :)

We did do a few extra rounds of container updates, so if any have submitted patches they should be up-to-date...
 
Top