log4 java script used by Go-To-Meeting launcher
A worldwide vulnerability was detected in software containing the so-called log4j java tool/component. To mitigate the risk of hacks / ransomware attacks they requested whether you could answer the following questions, with regard to the GoToMeeting Opener software package that we use, developed and distributed by your company.
- Does the application contain the log4j java-component?
- Is the used version of this component vulnerable for CVE-2021-44228?
- Do you already have a patched version of the application available?
- If no, when can this be expected?
- Is a workaround available?
My apologies for the inconvenience and many thanks for your help!
EvenSteven Our teams are continuing to investigate and either verifying that there is no impact or taking steps, where necessary and patching is available, to resolve the issue through security patches on our side. Except in exceptionally rare circumstances, where users have been notified, there is no further action to take on the customer side regarding this vulnerability.
You can reference this support article for updates around our findings: https://support.goto.com/meeting/help/logmeins-response-to-log4j