ARTICLE
15 December 2021

Urgent Cybersecurity Alert Regarding Apache Log4j

ML
McMillan LLP
Contributor
McMillan is a leading business law firm serving public, private and not-for-profit clients across key industries in Canada, the United States and internationally. With recognized expertise and acknowledged leadership in major business sectors, we provide solutions-oriented legal advice through our offices in Vancouver, Calgary, Toronto, Ottawa, Montréal and Hong Kong. Our firm values – respect, teamwork, commitment, client service and professional excellence – are at the heart of McMillan’s commitment to serve our clients, our local communities and the legal profession.
Canada's Minister of National Defence has issued a statement regarding a recently identified critical vulnerability in the Apache Log4j logging product.
Canada Technology
To print this article, all you need is to be registered or login on Mondaq.com.

Canada's Minister of National Defence has issued a statement regarding a recently identified critical vulnerability in the Apache Log4j logging product. The threat has potential for exploitation by bad actors for use in cybersecurity attacks, including against sensitive information assets. Open-source reporting indicates that the critical vulnerability is actively being scanned for and exploited.

It is being reported that various Canadian public agencies are temporarily taking down online services as a preventative measure, including the CRA, Metrolinx and thousands of government websites in Quebec.

The Canadian Centre for Cybersecurity has released technical guidance about the issue and has called on all Canadian organizations to immediately follow recommended steps to protect themselves from the vulnerability. The suggested steps include:

  1. internally reviewing all potentially impacted applications;
  2. if possible, upgrading to Apache Log4j version 2.15, which addresses the vulnerability
  3. if upgrading is not immediately possible, applying workarounds suggested by Apache; and
  4. reviewing logs for signs of compromise.

Canada's Minister of National Defence also directs organizations that depend on third-party service providers to engage them immediately to inquire about the actions they are taking.

If your organization uses Apache Log4j, please ensure that you are taking necessary steps to address the vulnerability noted above, including following the steps recommended by the Minister of National Defence and the Canadian Centre for Cybersecurity.

The foregoing provides only an overview and does not constitute legal advice. Readers are cautioned against making any decisions based on this material alone. Rather, specific legal advice should be obtained.

© McMillan LLP 2021

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

ARTICLE
15 December 2021

Urgent Cybersecurity Alert Regarding Apache Log4j

Canada Technology
Contributor
McMillan is a leading business law firm serving public, private and not-for-profit clients across key industries in Canada, the United States and internationally. With recognized expertise and acknowledged leadership in major business sectors, we provide solutions-oriented legal advice through our offices in Vancouver, Calgary, Toronto, Ottawa, Montréal and Hong Kong. Our firm values – respect, teamwork, commitment, client service and professional excellence – are at the heart of McMillan’s commitment to serve our clients, our local communities and the legal profession.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More