# Log4j vulnerability in ODK-X endoint?

**URL:** <https://forum.odk-x.org/t/log4j-vulnerability-in-odk-x-endoint/1592>\
**Category:** Support\
**Tags:** odk-x-sync-endpoint\
**Created:** [December 16, 2021, 8:39am UTC](https://forum.odk-x.org/t/log4j-vulnerability-in-odk-x-endoint/1592 "2021-12-16T08:39:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andreas](https://odkx.b-cdn.net/letter_avatar_proxy/v4/letter/a/ee7513/32.png) [@Andreas](https://forum.odk-x.org/u/Andreas)\
**Post date:** [December 16, 2021, 8:39am UTC](https://forum.odk-x.org/t/log4j-vulnerability-in-odk-x-endoint/1592/1 "2021-12-16T08:39:45Z")

</div>

Hello,

By my organisation I have been asked if my servers running ODK-X endpoint are vulnerable to the log4j hack.  
I don’t know much about the servers and I would appreciate your help answering this question.

All the best,  
Andreas

---

<div class="post-metadata">

**Author:** ![W\_Brunette](https://odkx.b-cdn.net/user_avatar/forum.odk-x.org/w_brunette/32/376_2.png) [@W\_Brunette](https://forum.odk-x.org/u/W_Brunette)\
**Post date:** [December 16, 2021, 4:27pm UTC](https://forum.odk-x.org/t/log4j-vulnerability-in-odk-x-endoint/1592/2 "2021-12-16T16:27:08Z")

</div>

Here is the Sync-Endpoint dependencies file:

> <https://github.com/odk-x/sync-endpoint/blob/master/pom.xml>

If you search for log4j you can see we are actually excluding it from our logging system as it conflicted and caused problems in the past.

So at a high level it does not appear to have an issue. However, not sure if one of the dependencies sync-endpoint depends on has a dependency deep in it’s code. As new versions come out we will be upgrading.

---

<div class="post-metadata">

**Author:** ![Emil](https://odkx.b-cdn.net/user_avatar/forum.odk-x.org/emil/32/3_2.png) [@Emil](https://forum.odk-x.org/u/Emil)\
**Post date:** [December 21, 2021, 3:23pm UTC](https://forum.odk-x.org/t/log4j-vulnerability-in-odk-x-endoint/1592/3 "2021-12-21T15:23:28Z")

</div>

Hello,

In addition to Waylon’s comment, the Tomcat server used by sync-endpoint should also not be affected (as per the official Tomcat website: [Apache Tomcat® - Apache Tomcat 8 vulnerabilities](https://tomcat.apache.org/security-8.html#:~:text=Code%20Execution%20via-,log4j,-CVE%2D2021%2D44228))

The other application exposed by sync-endpont is Nginx which is written in C and not affected by Log4j.

Best regards,  
Emil
