You are viewing an Archived item in your Knowledge Base, it is not publicly accessible.

NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • Contact Us
English (US)
NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish
  • Home
  • Password Boss Knowledgebase
  • Administrating Password Boss

Apache Log4j2 vulnerability (CVE-2021-44228)

Learn about the security vulnerability in the Apache Log4j2 library and how to protect yourself against it.

Written by Owen Parry

Updated at May 21st, 2026

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • AutoElevate Knowledgebase
    New to AutoElevate? START HERE AutoElevate Features & Troubleshooting Managing Rules in AutoElevate Integrations for AutoElevate AutoElevate FAQ Selling AutoElevate
  • Password Boss Knowledgebase
    Using Password Boss Administrating Password Boss Legacy Password Boss
  • CyberFOX DNS Filtering
    Getting Started with DNS Filtering DNS Filtering Concepts Network Requirements for DNS Filtering DNS Filtering Company and Location Setup Managing your DNS Filtering Policies Using Roaming Clients for DNS Filtering DNS Filtering Reports & Logs DNS Filtering Troubleshooting
  • Marketing Toolkit
    MSP Marketing & Education Toolkit CyberFOX Brand Guidelines
  • Changelogs for Autoelevate and Password Boss
  • CyberFOX Product Roadmap
  • Current Status
+ More

Table of Contents

Password Boss' services and applications are not affected by the Apache Log4j2 vulnerability (CVE-2021-44228)

Password Boss' services and applications are not affected by the Apache Log4j2 vulnerability (CVE-2021-44228)


Background
On 12/10/21, a high-severity security vulnerability in the Java-based log4j logging framework (CVE-2021-44228) was reported and began to be actively exploited on systems across the internet. This exploit, also known as "log4shell" or "shellshock, " provides a vector for remote code execution.

Since the vulnerability was made public, we have been actively reviewing and deep-diving into all our codebases, dependencies, infrastructure, and 3rd party vendors to see whether any part was affected. We are happy to report that nothing was found.

None of our web services are written or make use of any Java code or libraries. The only Java code in our stack is our Android mobile application, which was checked thoroughly, including all dependencies, and there is no usage of Log4j at all.

Security is a top priority at Password Boss, so we will continue to review & assess vulnerabilities as they become known to maintain and ensure security in your environments.

log4j2 vulnerability

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Deploying using GPO
  • DNS Filtering with Shared IPs (Carrier Grade NAT / CGNAT)
  • Disabling Password Boss on Websites
  • Logging into websites ⭐
Request a Demo
  • Get Pricing
  • Start Trial
  • Contact
  • Support Center
  • Login
Solutions
AutoElevate
  • AutoElevate Overview
  • Remove Admin Privilege
  • Just-in-Time Admin
  • Blocker
Password Manager
  • Password Manager Overview
  • Features
DNS Filtering
  • DNS Filtering Overview
MSPs
IT Departments
  • Overview
  • State and Local Government
  • K-12 Education
  • Manufacturing
  • Higher Education
Resources
  • Resource Center
  • Group Demos
  • Events
  • The Simple 7™
Company
  • About
  • Leadership
  • Culture & Values
  • News & Press
  • Awards
  • Partnerships
  • Referral Program
  • Trust Center
CyberFox Logo

CALL US (813) 578-8200

© 2025 CYBERFOX LLC ALL RIGHTS RESERVED | Privacy Policy | Terms of Service | Sitemap


Knowledge Base Software powered by Helpjuice

Expand