我没有注意到有关最近的Log4J漏洞(CVE-2021-44228)的任何消息或通信。Nutanix是否有一些正式公告与其产品组合有关的这种威胁的状态?
最好的答案Teixeirapaulo
\u00a0<\/p>
in this doc there are some information about theme.<\/p>
This survey is one of the largest studies of IT salary, skills, and certifications. It\u2019s the backbone of Skillsoft\u2019s annual IT Skills and Salary Report, which shares detailed insights on skills and certifications, compensation, skills gaps and challenges, and more for IT professionals at every stage of their career.<\/span><\/p> The survey typically takes 10-15 minutes to complete. You can bookmark your progress and pick up where you left off within one week of starting the survey. It\u2019s also completely anonymous. Skillsoft doesn\u2019t sell the data or share it with others.\u00a0<\/p> Participating in the survey is a great way to share how Nutanix certification and training has impacted your career. <\/span>Plus, anyone who completes the survey can enter to win a $100 gift card! <\/em><\/p> \u00a0<\/p> This article was written by Karlie Beil, Customer Marketing Specialist.\u00a0<\/p><\/div><\/div><\/div><\/div><\/div><\/section> \u00a0<\/p> \u00a9\ufe0f\ufe0f\ufe0f\ufe0f\ufe0f\ufe0f 2022 Nutanix, Inc. \u00a0All rights reserved. Nutanix, the Nutanix logo and all Nutanix product, feature and service names mentioned herein are registered trademarks or trademarks of Nutanix, Inc. in the United States and other countries. Other brand names mentioned herein are for identification purposes only and may be the trademarks of their respective holder(s). This post may contain links to external websites that are not part of Nutanix.com. Nutanix does not control these sites and disclaims all responsibility for the content or accuracy of any external site. Our decision to link to an external site should not be considered an endorsement of any content on such a site. This post may contain express and implied forward-looking statements, which are not historical facts and are instead based on our current expectations, estimates and beliefs. The accuracy of such statements involves risks and uncertainties and depends upon future events, including those that may be beyond our control, and actual results may differ materially and adversely from those anticipated or implied by such statements. Any forward-looking statements included herein speak only as of the date hereof and, except as required by law, we assume no obligation to update or otherwise revise any of such forward-looking statements to reflect subsequent events or circumstances.<\/p>","id":40862,"featuredImage":"https:\/\/uploads-us-west-2.insided.com\/nutanix-us\/attachment\/1b5db37d-c54b-4002-8bee-065c799897b2_thumb.png","label":"Blog","replyCount":0,"views":156,"post":{"id":61075,"author":{"id":113632,"url":"\/members\/karlie-beil-113632","name":"Karlie Beil","avatar":"https:\/\/uploads-us-west-2.insided.com\/nutanix-us\/icon\/200x200\/1581aab3-bcf6-49f4-b2fb-3d11e8c010dc.png","userTitle":"Community Manager","rank":{"isBold":false,"isItalic":false,"isUnderline":false,"name":"Community Manager","color":"#0873ba"},"userLevel":2},"content":" The 2022 IT Salary & Skills Survey is now open, and you can participate!<\/strong> <\/span><\/p> This survey is one of the largest studies of IT salary, skills, and certifications. It\u2019s the backbone of Skillsoft\u2019s annual IT Skills and Salary Report, which shares detailed insights on skills and certifications, compensation, skills gaps and challenges, and more for IT professionals at every stage of their career.<\/span><\/p> The survey typically takes 10-15 minutes to complete. You can bookmark your progress and pick up where you left off within one week of starting the survey. It\u2019s also completely anonymous. Skillsoft doesn\u2019t sell the data or share it with others.\u00a0<\/p> Participating in the survey is a great way to share how Nutanix certification and training has impacted your career. <\/span>Plus, anyone who completes the survey can enter to win a $100 gift card! <\/em><\/p> \u00a0<\/p> This article was written by Karlie Beil, Customer Marketing Specialist.\u00a0<\/p><\/div><\/div><\/div><\/div><\/div><\/section> \u00a0<\/p> \u00a9\ufe0f\ufe0f\ufe0f\ufe0f\ufe0f\ufe0f 2022 Nutanix, Inc. \u00a0All rights reserved. Nutanix, the Nutanix logo and all Nutanix product, feature and service names mentioned herein are registered trademarks or trademarks of Nutanix, Inc. in the United States and other countries. Other brand names mentioned herein are for identification purposes only and may be the trademarks of their respective holder(s). This post may contain links to external websites that are not part of Nutanix.com. Nutanix does not control these sites and disclaims all responsibility for the content or accuracy of any external site. Our decision to link to an external site should not be considered an endorsement of any content on such a site. This post may contain express and implied forward-looking statements, which are not historical facts and are instead based on our current expectations, estimates and beliefs. The accuracy of such statements involves risks and uncertainties and depends upon future events, including those that may be beyond our control, and actual results may differ materially and adversely from those anticipated or implied by such statements. Any forward-looking statements included herein speak only as of the date hereof and, except as required by law, we assume no obligation to update or otherwise revise any of such forward-looking statements to reflect subsequent events or circumstances.<\/p>","url":"\/education-blog-153\/add-your-voice-to-the-it-skills-and-salary-survey-40862?postid=61075#post61075","creationDate":"2022-05-12T20:00:15+0000","relativeCreationDate":"28 days ago"},"contentType":"article","type":3,"likes":0,"hasCurrentUserLiked":false},"phrases":{"Forum":{"{n} year|{n} years":"{n} year|{n} years","{n} month|{n} months":"{n} month|{n} months","{n} day|{n} days":"{n} day|{n} days","{n} hour|{n} hours":"{n} hour|{n} hours","{n} minute|{n} minutes":"{n} minute|{n} minutes","just":"just now","{plural} ago":"{plural} ago"}}}">
我没有注意到有关最近的Log4J漏洞(CVE-2021-44228)的任何消息或通信。Nutanix是否有一些正式公告与其产品组合有关的这种威胁的状态? 最好的答案Teixeirapaulo2021年12月13日,02:36 \u00a0<\/p> in this doc there are some information about theme.<\/p> \u00a0<\/p> in this doc there are some information about theme.<\/p> 任何更新 ?PDF不会自行更新。 您好,不知何故,我错过了Nutanix的一些更新,因为现在哪些产品最终受到影响,以及应该采取哪些步骤。 HOWDY-乔恩(Jon)在这里的工程 - 该链接的PDF每天至少每天更新一次,直到我们完全驱动到地面为止。 另外,如果您在那里有一个用户帐户,则应该从支持门户网站获得电子邮件。 恕我直言,安全警报应该淘汰,这意味着您应该自动获得它们,除非您专门将其关闭,否则在这里:https://portal.nutanix.com/page/subscriptions 示例:这是我第一次出门时收到的警报的屏幕截图。 \u00a0<\/p> The PDF at that link will be updated at least once per day until we\u2019ve got this driven completely to ground.<\/p> \u00a0<\/p> Also, you should be getting an email blast from the support portal if you have a user account there.\u00a0<\/p> \u00a0<\/p> IMHO, the security alerts\u00a0should<\/em><\/strong>\u00a0be out-out, meaning you should get them automagically unless you\u2019ve specifically turned them off, here:\u00a0https:\/\/portal.nutanix.com\/page\/subscriptions<\/a><\/p> \u00a0<\/p> example: Here\u2019s a screenshot of the alert that I got when this first went out.<\/p> 乔恩,感谢您的更新。PDF对社区版本一无所知,也没有列出脆弱产品的特定版本。并非所有簇都将在最新的LTS/STS上运行。 另外,如果Prism Central(所有版本)很脆弱,这是否意味着Prism元素也很脆弱? Also if Prism Central (all versions) is vulnerable, does that\u00a0mean that Prism Element is\u00a0also vulnerable?<\/p>","quoteUsername":"waddles","translations":{"Common":{"like":"Like","unlike":"Unlike"},"Forum":{"Quote":"Quote","Share":"Share"}}}">
乔恩,感谢您的更新。PDF对社区版本一无所知,也没有列出脆弱产品的特定版本。并非所有簇都将在最新的LTS/STS上运行。 另外,如果Prism Central(所有版本)很脆弱,这是否意味着Prism元素也很脆弱? @waddles→您提出好积分,感谢您的伸出援手。 不列出特定版本:我们确实说“所有受支持的版本”,但是您是对的,我们应该更具体。具体来说,我们指的是由EOL计划定义的支持版本,此处: 个人电脑:https://download.nutanix.com/misc/pc_eol/pc_eol.pdf 我要求团队在SA中添加对这些链接的参考,以便每个人都清楚。 关于CE→另一个好点,它没有受到影响,我要求团队添加一条线,即AOS(CE)未受到影响。 Prism元素只是AOS的UI,因此它属于AOS行项目。我会看看我们是否也可以更清楚 Jon, thanks for the update. The PDF says nothing about Community Edition and does not list specific versions of vulnerable products. Not all clusters will be running on latest LTS\/STS.<\/p>\t Also if Prism Central (all versions) is vulnerable, does that\u00a0mean that Prism Element is\u00a0also vulnerable?<\/p>\t<\/div><\/content-quote> @Waddles \u2192\u00a0You bring up good points, thanks for reaching out.<\/p> RE not listing specific versions: We do say \u201cAll Supported Versions\u201d, but you\u2019re right, we should be more specific. What we\u2019re referring to, specifically, is supported versions as defined by our EOL schedules, here:\u00a0<\/p> PC:\u00a0https:\/\/download.nutanix.com\/misc\/PC_EOL\/PC_EOL.pdf<\/a> \u00a0<\/p> I\u2019ve asked the team to add a reference to these links in the SA so its clear for everyone.<\/p> \u00a0<\/p> About CE \u2192\u00a0Another good point, It is not impacted and I\u2019ve asked the team to add a line i.e. AOS (CE) Not Impacted.\u00a0<\/p> \u00a0<\/p> Prism Element is just the UI for AOS, so it falls under AOS line item. I\u2019ll see if we can make that more clear too<\/p>","quoteUsername":"Jon","translations":{"Common":{"like":"Like","unlike":"Unlike"},"Forum":{"Quote":"Quote","Share":"Share"}}}">
乔恩,感谢您的更新。PDF对社区版本一无所知,也没有列出脆弱产品的特定版本。并非所有簇都将在最新的LTS/STS上运行。 另外,如果Prism Central(所有版本)很脆弱,这是否意味着Prism元素也很脆弱? v1.6现在发布了,该v1.6呼吁没有受到影响,现在我们已经有了指向支持版本的特定链接来澄清这一点。我们还为Prism元素添加了澄清,这全都基于您的反馈。感谢您的贡献。 干杯, 乔恩 Jon, thanks for the update. The PDF says nothing about Community Edition and does not list specific versions of vulnerable products. Not all clusters will be running on latest LTS\/STS.<\/p>\t Also if Prism Central (all versions) is vulnerable, does that\u00a0mean that Prism Element is\u00a0also vulnerable?<\/p>\t<\/div><\/content-quote> v1.6 now posted, which calls out CE not impacted, and now we\u2019ve got specific links to supported versions to clarify that. We\u2019ve also added a clarification for Prism Element, which was all based on your feedback. Thanks for the contribution.<\/p> \u00a0<\/p> Cheers,<\/p> Jon<\/p>","quoteUsername":"Jon","translations":{"Common":{"like":"Like","unlike":"Unlike"},"Forum":{"Quote":"Quote","Share":"Share"}}}">
谢谢乔恩。我使用自己的扫描 并发现图书馆仅在Prism Central中用于Elasticsearch。希望该命令可以用作通用搜索,以防人们需要其他应用程序。 在没有缓解策略的情况下,您能否确认仅通过经过身份验证的API调用才能访问Elasticsearch,并且在LAN地址上可访问的端口上不聆听? and found the library is only used in Prism Central for elasticsearch. Hopefully that command may be useful as a general purpose search in case people need it for other applications.<\/p> In the absence of a mitigation strategy, can you confirm that elasticsearch is only accessible through authenticated API calls and is not listening on a port that is accessible on a LAN address?<\/p>","quoteUsername":"waddles","translations":{"Common":{"like":"Like","unlike":"Unlike"},"Forum":{"Quote":"Quote","Share":"Share"}}}">
我会更好地做一个,根本不使用Elasticsearch,很久以前就添加了该软件包,并且从未被删除。我们将在2021.9.0.3删除 输入您的用户名或电子邮件地址。我们将向您发送带有指令的电子邮件以重置您的密码。Take the survey today!<\/strong><\/a><\/h3>
Take the survey today!<\/strong><\/a><\/h3>
log4j漏洞
9回复
坦率地说,在传播更新以及如何修复方面,其他供应商(例如VMware)做好了更好的准备
Other vendors like vmware are frankly much better prepared in terms of spreading updates and how to fix\u00a0<\/p>","quoteUsername":"emu0099","translations":{"Common":{"like":"Like","unlike":"Unlike"},"Forum":{"Quote":"Quote","Share":"Share"}}}">
AOS:https://download.nutanix.com/misc/aos_eol/aos_eol.pdf
文件:https://download.nutanix.com/misc/files_eol/files_eol.pdf
一般生活政策://www.jhbzcj.com/support-services/product-support/support-policies-and-faqs?show=accordion-0
AOS:\u00a0https:\/\/download.nutanix.com\/misc\/AOS_EOL\/AOS_EOL.pdf<\/a>
Files:\u00a0https:\/\/download.nutanix.com\/misc\/FILES_EOL\/FILES_EOL.pdf<\/a>
General End of Life Policies:\u00a0\/\/www.jhbzcj.com\/support-services\/product-support\/support-policies-and-faqs?show=accordion-0<\/a><\/p>
$ find/-xdev -name'*.jar'2>/dev/null |XARGS -I文件SH -C“如果Zipgrep'^版本= 2'file'*log4j*'2>/dev/null;然后在文件中找到echo; fi; fi“
$ find \/ -xdev -name '*.jar' 2>\/dev\/null | xargs -I FILE sh -c \"if zipgrep '^version=2' FILE '*log4j*' 2>\/dev\/null; then echo found in FILE; fi\"<\/code><\/pre>
Functional","cookiepolicy.modal.level2":"Normal
Functional + analytics","cookiepolicy.modal.level3":"Complete
Functional + analytics + social media + embedded videos"}}}">