Hi,
while scanning our infrastructure for exposed instances that might use log4j we noticed that this applies to freeIPA in some places as well.
Is there any official statement how freeIPA is affected by this and what measures need to be taken?
For some external services we offer we have an exposes IPA instance. We took it offline for now just to be sure because we do not know if this issue is exploitable or not in this instance. But now users cannot change or reset their passwords. This is manageable for a few days but actually we need to bring this back online relatively soon.
So is there any initial judgement on this?
Please see here:
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org/message/CL4QVCQEOUBJ4LYA7AXQPBF4JNJEQULO/
I am closing this "bug". For questions like that please use the freeipa-users@ mailing list instead.
Metadata Update from @abbra: - Issue close_status updated to: invalid - Issue status updated to: Closed (was: Open)