Skip to main content
Solved

Third-Party Security Issue

  • December 10, 2021
  • 62 replies
  • 342 views

Show first post

62 replies

Forum|alt.badge.img+7
  • New Contributor
  • December 21, 2021

@tlarkin See Aaron's response above. I didn't want you to miss it.  😀


Can you get Aaron_Kiemele a badge like yours that states his position or employment status with Jamf. Right now it looks like some random person off the street. 


Forum|alt.badge.img+6
  • New Contributor
  • December 21, 2021

Since it's not updated here yet.  Healthcare Listener and Infrastructure Manager applications have been updated with Log4j 2.17 and should be available in your product assets in your account if you use it. 
The New HCL/JIM version is 2.2.2.
Happy patching.


jmahlman
Forum|alt.badge.img+17
  • Valued Contributor
  • December 22, 2021

My cyber team is wondering if we can update the lo4j library to 2.17 manually (so it can be removed from scans). Will this work?


Alitejawi
Forum|alt.badge.img+1
  • New Contributor
  • December 22, 2021

My cyber team is wondering if we can update the lo4j library to 2.17 manually (so it can be removed from scans). Will this work?


Yes, you can do that, that's what I have done as well. I followed this, but replaced 2.16.0 for 2.17.0: https://docs.jamf.com/technical-articles/Mitigating_the_Apache_Log4j_2_Vulnerability.html

Worked perfectly fine. 


Forum|alt.badge.img
  • New Contributor
  • December 28, 2021

Great work thank you for sharing this information.

myccpay account


Forum|alt.badge.img+10
  • Author
  • Employee
  • Answer
  • December 29, 2021

UPDATE 12/28

We are aware of CVE-2021-44832 that was remediated in log4j 2.17.1. Based on public disclosures to date, this vulnerability does not affect any Jamf products or services. The conditions required for the exploitation of the vulnerability are not met by Jamf’s use of the log4j library. No further action is required at this time. We will continue to monitor the situation and will report on new information as it becomes available.


Forum|alt.badge.img+9
  • Valued Contributor
  • January 3, 2022

Do you even work for JAMF?  How do we know this is credible information???

 

Paul

President of the United Federation, because my signature says so.


AJPinto
Forum|alt.badge.img+26
  • Legendary Contributor
  • January 3, 2022

Do you even work for JAMF?  How do we know this is credible information???

 

Paul

President of the United Federation, because my signature says so.


Aaron Kiemele is JAMFs Chief Information Security Officer. However I totally agree. There should be some kind of badge of some sort so we know this is a JAMF employee.

 

He did sign one of his posts 2 weeks ago in this thread, looks like it was originally an email. Not a source of trust by any means but it is what it is. I do find it funny a Chief Information Security Officer feels no need to prove his information is trustworthy. Suppose typical ivory tower nonsense and no one under him has the courage to tell him he is doing this wrong. We should have gotten these communications in emails.


Forum|alt.badge.img+6
  • New Contributor
  • January 3, 2022

Aaron Kiemele is JAMFs Chief Information Security Officer. However I totally agree. There should be some kind of badge of some sort so we know this is a JAMF employee.

 

He did sign one of his posts 2 weeks ago in this thread, looks like it was originally an email. Not a source of trust by any means but it is what it is. I do find it funny a Chief Information Security Officer feels no need to prove his information is trustworthy. Suppose typical ivory tower nonsense and no one under him has the courage to tell him he is doing this wrong. We should have gotten these communications in emails.


True. I did get a notice from my internal JAMF customer support contact, wh pointed me to his/this thread when I was asking for info two weeks ago. For what it's worth [from me as another unknown person in the community 😉 ]

I agree staff should be easily identifiable when they post though.

Donald


IMPORTANT WARNING: This message is intended for the use of the person or entity to which it is addressed and may contain information that is privileged and confidential, the disclosure of which is governed by applicable law. If the reader of this message is not the intended recipient, or the employee or agent responsible for delivering it to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this information is strictly prohibited. Thank you for your cooperation.

Forum|alt.badge.img+10
  • Author
  • Employee
  • January 3, 2022
True. I did get a notice from my internal JAMF customer support contact, wh pointed me to his/this thread when I was asking for info two weeks ago. For what it's worth [from me as another unknown person in the community 😉 ]

I agree staff should be easily identifiable when they post though.

Donald


IMPORTANT WARNING: This message is intended for the use of the person or entity to which it is addressed and may contain information that is privileged and confidential, the disclosure of which is governed by applicable law. If the reader of this message is not the intended recipient, or the employee or agent responsible for delivering it to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this information is strictly prohibited. Thank you for your cooperation.

Thank you, this is a good point. I will look into how we might best improve.  

Any ambiguous information can also be authenticated via the release notes here, by contacting your Customer Success rep, or reaching out to support@jamf.com

Aaron Kiemele
Chief Information Security Officer, Jamf


Forum|alt.badge.img+9
  • Valued Contributor
  • January 4, 2022

Thank you, this is a good point. I will look into how we might best improve.  

Any ambiguous information can also be authenticated via the release notes here, by contacting your Customer Success rep, or reaching out to support@jamf.com

Aaron Kiemele
Chief Information Security Officer, Jamf


Our IAs aren't going to accept "New Contributor III" as an official source of information.  Until this is in a KB, or you provide proof of your claimed credentials, I have asked customer support for the information in an verifiable authentic manner.


CalleyO
Forum|alt.badge.img+15
  • Employee
  • January 6, 2022

Hello Jamf Nation! Community Moderator, Calley here. Thank you for raising the concern about identifying our Jamf employees in our Jamf Nation Community. Today we began rolling out the employee role badge next to a Jamf employee's name. However, this is a rollout, so not every Jamf will have a badge today, and we appreciate your patience as we work toward this goal. In the meantime, if you do have questions regarding any community members' status, please reach out via DM, Slack me on MacAdmin, or email at jamfnation@jamf.com.