<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log4j2 Vulnerability in Installing and Upgrading</title>
    <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407176#M11419</link>
    <description>&lt;P&gt;If i download the V8.0.1 talend open studio and migrate my jobs from 7.3.1 to the latest one will it fix the issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Dec 2021 06:36:18 GMT</pubDate>
    <dc:creator>veeaar</dc:creator>
    <dc:date>2021-12-23T06:36:18Z</dc:date>
    <item>
      <title>Log4j2 Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407174#M11417</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will the mitigation provided for the Talend Studio for Log4j "-Dlog4j2.formatMsgNoLookups=true"&amp;nbsp;- will it work for Talend Open Studio 7.3, or any other way that help to mitigate the issue in TOS.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 23:23:09 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407174#M11417</guid>
      <dc:creator>Yogesh0204</dc:creator>
      <dc:date>2024-11-15T23:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j2 Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407175#M11418</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Regarding of this response Publication Date: December 22, 2021 &lt;A href="https://www.talend.com/security/incident-response/" alt="https://www.talend.com/security/incident-response/" target="_blank"&gt;https://www.talend.com/security/incident-response/&lt;/A&gt;, remediation for Talend Open Source is not in scope. We are trying to work on remediation for talend open studio and will come back to you as soon as possible.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Sabrina&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 03:34:20 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407175#M11418</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-12-23T03:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j2 Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407176#M11419</link>
      <description>&lt;P&gt;If i download the V8.0.1 talend open studio and migrate my jobs from 7.3.1 to the latest one will it fix the issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 06:36:18 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407176#M11419</guid>
      <dc:creator>veeaar</dc:creator>
      <dc:date>2021-12-23T06:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j2 Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407177#M11420</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I’m afraid Talend 8 version was released prior to the vulnerability being revealed.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Sabrina&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 08:45:22 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407177#M11420</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-12-23T08:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j2 Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407178#M11421</link>
      <description>&lt;P&gt;Thanks Sabrina. My IT Security Team asked me to look into the R2021-12 (cumulative patch). Is this patch applicable for Talend Open Studio For Data Integration (7.3.1.20200219_1130)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using the open studio and we have our production go live in 15 days &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please confirm what are the options we have at this time to fix the log4j issues for this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for your quick response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 14:51:13 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407178#M11421</guid>
      <dc:creator>veeaar</dc:creator>
      <dc:date>2021-12-23T14:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j2 Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407179#M11422</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We do not supply patches for the Open Studio releases. Patches are specific to Talend Service, the version of the Talend Service, the severity of the risk, and other mitigating controls Talend maintains.&lt;/P&gt;&lt;P&gt;You can find mitigation instructions for existing products here….&lt;/P&gt;&lt;P&gt;Publication Date: December 23, 2021: &lt;A href="https://www.talend.com/security/incident-response/" alt="https://www.talend.com/security/incident-response/" target="_blank"&gt;https://www.talend.com/security/incident-response/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;As remediation for Talend Open Source is not in scope, we have already escalated it to our IT security team to see if there is any graceful workaround and solution for talend open studio and then come back to you as soon as possible.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Sabrina&lt;/P&gt;</description>
      <pubDate>Fri, 24 Dec 2021 02:37:02 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407179#M11422</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-12-24T02:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j2 Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407180#M11423</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Any news for Talend Open Studio 7.3 or 8.0 ?&lt;/P&gt;&lt;P&gt;When will it comes into your scope ?&lt;/P&gt;&lt;P&gt;In the meantime, is there a way for us to prevent TOS to include vulnerable log4j jar files into our builds (TOS do so even when log4j is not enabled for a project !) ?&lt;/P&gt;&lt;P&gt;Thanks in advance for your help&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 15:30:19 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407180#M11423</guid>
      <dc:creator>ABD2</dc:creator>
      <dc:date>2021-12-27T15:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j2 Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407181#M11424</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We’re working on updating the TOS with the Log4j fix and will keep you update to your issue.&lt;/P&gt;&lt;P&gt; Meanwhile the mitigation steps that we have described in the Talend Help (incident response) apply to TOS as well.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.talend.com/security/incident-response/" alt="https://www.talend.com/security/incident-response/" target="_blank"&gt;https://www.talend.com/security/incident-response/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Sabrina&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 03:47:43 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407181#M11424</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-12-28T03:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j2 Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407182#M11425</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The mitigation steps are now located on help.talend.com: &lt;A href="https://document-link.us.cloud.talend.com/talend_log4j2_cve_statement?lang=en&amp;amp;version=latest&amp;amp;env=prd" alt="https://document-link.us.cloud.talend.com/talend_log4j2_cve_statement?lang=en&amp;amp;version=latest&amp;amp;env=prd" target="_blank"&gt;https://document-link.us.cloud.talend.com/talend_log4j2_cve_statement?lang=en&amp;amp;version=latest&amp;amp;env=prd&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which provides all the workarounds for studio.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Sabrina&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 06:55:03 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407182#M11425</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-12-31T06:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j2 Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407183#M11426</link>
      <description>&lt;P&gt;For Talend Open Studio 7.3 or 8.0,  are the mitigation steps proposed essential when our projects properties don't use log4j (Check Box not checked).  I know we still have all the jar files generated in anyways. &lt;/P&gt;&lt;P&gt;Thanks in advance for the help. &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="0695b00000LzQorAAF.png"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/132816iC3D0DD2E9B782228/image-size/large?v=v2&amp;amp;px=999" role="button" title="0695b00000LzQorAAF.png" alt="0695b00000LzQorAAF.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 09:05:46 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407183#M11426</guid>
      <dc:creator>abcdmichel</dc:creator>
      <dc:date>2022-01-05T09:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j2 Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407184#M11427</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm afraid we cannot give 100% assurances of this kind situation(uncheck log4j box).&lt;/P&gt;&lt;P&gt;Note: The mitigation steps that we have described in the Talend Help apply to TOS as well.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Sabrin&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 09:43:55 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j2-Vulnerability/m-p/2407184#M11427</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2022-01-05T09:43:55Z</dc:date>
    </item>
  </channel>
</rss>

