Title | Is Stata affected by the Log4j vulnerability (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832)? | |
Author | James Hassell, StataCorp |
This is in reference to CVE-2021-44228 and the subsequent CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832, which impact software that uses certain versions of Apache Log4j.
Stata 15 and Stata 16 do not use Log4j and are not affected.
Stata 17's core features do not use Log4j. However, the experimental H2O feature does use Log4j. Stata 17 updated to 17 January 2022 includes a patched version of H2O that mitigates the vulnerabilities described in the CVEs. Importantly, if you are not using h2o commands, the affected Log4j library will not be loaded by Stata even if your Stata is not updated.
On 14 December 2021, we released an update that included the then-latest H2O version, 3.34.0.5. H2O 3.34.0.5 incorporated Log4j 2.15, addressing CVE-2021-44228.
On 15 December 2021, it was reported that the fix addressing CVE-2021-44228 in Apache Log4j 2.15 was incomplete in certain non-default configurations, as described in CVE-2021-45046.
On 16 December 2021, we released another update to Stata 17 that included H2O version 3.34.0.6. H2O 3.34.0.6 used the patched Log4j library version 2.16, addressing both CVE-2021-44228 and CVE-2021-45046.
On 17 January 2022, we released another update to Stata 17 that includes H2O version 3.36.0.1. H2O 3.36.0.1 uses the patched Log4j library version 2.17.1, which addresses both CVE-2021-45105 and CVE-2021-44832.
The latest updates can be installed in Stata 17 by typing update all in the Stata Command window. A fully updated Stata 17 is not affected by the CVEs described in this FAQ.
If you are unable to update your Stata installation, the H2O library including the affected Log4j library can be removed from the Stata installation. You can safely delete <stata_installation_directory>/ado/base/jar/libstata-h2o.jar to remove any possibility of the library being loaded.
Learn
Free webinars
NetCourses
Classroom and web training
Organizational training
Video tutorials
Third-party courses
Web resources
Teaching with Stata
© Copyright 1996–2024 StataCorp LLC. All rights reserved.
×
We use cookies to ensure that we give you the best experience on our website—to enhance site navigation, to analyze usage, and to assist in our marketing efforts. By continuing to use our site, you consent to the storing of cookies on your device and agree to delivery of content, including web fonts and JavaScript, from third party web services.
Cookie Settings
Last updated: 16 November 2022
StataCorp LLC (StataCorp) strives to provide our users with exceptional products and services. To do so, we must collect personal information from you. This information is necessary to conduct business with our existing and potential customers. We collect and use this information only where we may legally do so. This policy explains what personal information we collect, how we use it, and what rights you have to that information.
These cookies are essential for our website to function and do not store any personally identifiable information. These cookies cannot be disabled.
This website uses cookies to provide you with a better user experience. A cookie is a small piece of data our website stores on a site visitor's hard drive and accesses each time you visit so we can improve your access to our site, better understand how you use our site, and serve you content that may be of interest to you. For instance, we store a cookie when you log in to our shopping cart so that we can maintain your shopping cart should you not complete checkout. These cookies do not directly store your personal information, but they do support the ability to uniquely identify your internet browser and device.
Please note: Clearing your browser cookies at any time will undo preferences saved here. The option selected here will apply only to the device you are currently using.