On Friday 10th December, Ripple Treasury was informed of a vulnerability (CVE-2021-44228) on multiple versions of the Apache Log4j utility.
Please note, we do not use Log4j in our development. At this time, we have no reason to believe that there is an associated risk to our customers or services. However, we take all security-related issues extremely seriously, we continue to exercise an abundance of caution; We are working with Alert Logic, our intrusion detection service, to ensure we have increased scanning and alerting in relation to this vulnerability. If through our investigation, we learn of any customer impact, we will promptly notify any affected customers and provide them with information necessary to remedy related risks in a timely and effective manner.
You can find out more information regarding CVE-2021-44228, within Java logging library here: Apache Log4j 2 Remote Code Execution Vulnerability
Copyright 2025 Ripple Labs Inc.
