Is Erlang OTP vulnerable to Apache Log4J exploit CVE-2021-44228?

I have Erlang OTP 21 v10.0.1 (v21.0.1) installed on my machine. Is this version impacted by the vulnerability? I tried to check online but couldn’t find any confirmation if so.

3 Likes

Wikipedia (C):

Apache Log4j is a Java-based logging utility originally written by Ceki Gülcü. 
It is part of the Apache Logging Services, a project of the Apache Software Foundation. 
Log4j is one of several Java logging frameworks. 

I suppose no, because Erlang is not a Java and don’t use Log4j by default. Of course, if Erlang project by some reason has an integration with Log4j - then yes :upside_down_face:. But Erlang himself is invulnerable.

4 Likes