Hello
We just applied the latest maintenance patch to our 11.32. Commvault environment a few days ago to bring us to 11.32.128 (from 11.32.125) and I noticed this morning scans showed a log4j vulnerability.
Plugin Output:
Path : C:\Program Files\Commvault\ContentStore\CVCIEngine\CvPreviewHome\webapps\CvContentPreviewGenApp\WEB-INF\lib\log4j-core-2.17.1.jar
Installed version : 2.17.1
Fixed version : 2.25.3
Path : C:\Program Files\Commvault\ContentStore\MessageQueue\lib\optional\log4j-core-2.24.3.jar
Installed version : 2.24.3
Fixed version : 2.25.3
Is there a fix or patch that Commvault will release to address this. Maybe in the next months maintenance release? Any input would be appreciated.
Thanks
BC


