<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[log4j auch in 13.8.1]]></title><description><![CDATA[<p dir="auto">hallo, leider enthält die Version 13.8.1 immer noch eine Sicherheitslücke:</p>
<pre><code>C:\Users\ECM\Downloads\Log4j Scan\Log4j Scan&gt;log4j2-scan.exe "C:\Program Files\MediathekView"
Logpresso CVE-2021-44228 Vulnerability Scanner 2.6.1 (2021-12-23)
Scanning directory: C:\Program Files\MediathekView
[*] Found CVE-2021-45046 (log4j 2.x) vulnerability in C:\Program Files\MediathekView\MediathekView.jar, log4j 2.15.0

Scanned 73 directories and 365 files
Found 1 vulnerable files
Found 0 potentially vulnerable files
Found 0 mitigated files
Completed in 3.22 seconds
</code></pre>
<p dir="auto">Viele Grüße,<br />
Eckhard</p>
]]></description><link>https://forum.mediathekview.de/topic/4556/log4j-auch-in-13-8-1</link><generator>RSS for Node</generator><lastBuildDate>Wed, 22 Jul 2026 19:56:54 GMT</lastBuildDate><atom:link href="https://forum.mediathekview.de/topic/4556.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 29 Dec 2021 20:45:00 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to log4j auch in 13.8.1 on Thu, 30 Dec 2021 13:09:15 GMT]]></title><description><![CDATA[<p dir="auto">Hier gibt es einen Scanner für Windows 32/64 aus einem github-Issue als zip-Datei 13.9.0 ist sauber, 13.8.1 moderat :D<br />
<a href="https://github.com/Qualys/log4jscanwin" target="_blank" rel="noopener noreferrer nofollow ugc">README Lesen!</a></p>
]]></description><link>https://forum.mediathekview.de/post/29500</link><guid isPermaLink="true">https://forum.mediathekview.de/post/29500</guid><dc:creator><![CDATA[[[global:former-user]]]]></dc:creator><pubDate>Thu, 30 Dec 2021 13:09:15 GMT</pubDate></item><item><title><![CDATA[Reply to log4j auch in 13.8.1 on Thu, 30 Dec 2021 10:10:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/eckhardm" aria-label="Profile: eckhardm">@<bdi>eckhardm</bdi></a> sagte in <a href="/post/29484">log4j auch in 13.8.1</a>:</p>
<blockquote>
<p dir="auto">@oida Die Angreifbarkeit einer Clientapplikation ist tatsächlich fraglich. Aber die Entwickler haben genau wegen des Log4j-Themas eine neue Version released. Es kann sein, dass zukünftig aber Virenscanner etc. die Anwendung in Quarantäne nehmen. Daher sollte man das Problem trotzdem angehen.</p>
</blockquote>
<p dir="auto">Wir haben vorzeitig die neue Version released weil einige User panisch wurden obwohl kein wirkliches Risiko bestand. Die noch vorhandene „Lücke“ mit der jetzigen log4j2 Version in 13.8.1 ist noch weniger relevant.</p>
<p dir="auto">Wir haben in den alten Versionen eine Nutzungsmöglichkeit gefunden: Dazu musste der Nutzer am Rechner sitzend in einem Dialog in ein Textfeld händisch das Angriffskommando eintippen, dann wurde das an der Stelle auch umgesetzt. In meiner Bewertung ist dem Nutzer dann aber auch nicht mehr zu helfen wenn er das tut 😳 Mit 13.8.1 ist das schon behoben, der Rest wird mit 13.9 aktualisiert.</p>
]]></description><link>https://forum.mediathekview.de/post/29497</link><guid isPermaLink="true">https://forum.mediathekview.de/post/29497</guid><dc:creator><![CDATA[DerReisende77]]></dc:creator><pubDate>Thu, 30 Dec 2021 10:10:24 GMT</pubDate></item><item><title><![CDATA[Reply to log4j auch in 13.8.1 on Thu, 30 Dec 2021 06:59:52 GMT]]></title><description><![CDATA[<p dir="auto">@oida<br />
In den <a href="https://github.com/mediathekview/MediathekView/blob/develop/CHANGELOG.md" target="_blank" rel="noopener noreferrer nofollow ugc">Änderungshinweisen</a> zur kommenden Version 13.9.0 steht es schon drin.</p>
]]></description><link>https://forum.mediathekview.de/post/29493</link><guid isPermaLink="true">https://forum.mediathekview.de/post/29493</guid><dc:creator><![CDATA[MenchenSued]]></dc:creator><pubDate>Thu, 30 Dec 2021 06:59:52 GMT</pubDate></item><item><title><![CDATA[Reply to log4j auch in 13.8.1 on Wed, 29 Dec 2021 21:22:30 GMT]]></title><description><![CDATA[<p dir="auto">@oida Die Angreifbarkeit einer Clientapplikation ist tatsächlich fraglich. Aber die Entwickler haben genau wegen des Log4j-Themas eine neue Version released. Es kann sein, dass zukünftig aber Virenscanner etc. die Anwendung in Quarantäne nehmen. Daher sollte man das Problem trotzdem angehen.</p>
]]></description><link>https://forum.mediathekview.de/post/29484</link><guid isPermaLink="true">https://forum.mediathekview.de/post/29484</guid><dc:creator><![CDATA[EckhardM]]></dc:creator><pubDate>Wed, 29 Dec 2021 21:22:30 GMT</pubDate></item><item><title><![CDATA[Reply to log4j auch in 13.8.1 on Wed, 29 Dec 2021 21:13:58 GMT]]></title><description><![CDATA[<p dir="auto">@oida Richtig, trotzdem besteht noch Handlungsbedarf.</p>
]]></description><link>https://forum.mediathekview.de/post/29482</link><guid isPermaLink="true">https://forum.mediathekview.de/post/29482</guid><dc:creator><![CDATA[EckhardM]]></dc:creator><pubDate>Wed, 29 Dec 2021 21:13:58 GMT</pubDate></item></channel></rss>