# Announcement: Holistics IS NOT affected by the Log4j Exploit

**URL:** <https://community.holistics.io/t/announcement-holistics-is-not-affected-by-the-log4j-exploit/605>\
**Category:** News from Holistics\
**Created:** [December 14, 2021, 10:13am UTC](https://community.holistics.io/t/announcement-holistics-is-not-affected-by-the-log4j-exploit/605 "2021-12-14T10:13:58Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![anthonytd](https://community.holistics.io/user_avatar/community.holistics.io/anthonytd/32/374_2.png) [@anthonytd](https://community.holistics.io/u/anthonytd)\
**Post date:** [December 14, 2021, 10:13am UTC](https://community.holistics.io/t/announcement-holistics-is-not-affected-by-the-log4j-exploit/605/1 "2021-12-14T10:13:58Z")

</div>

## **Background**

“Log4Shell is a zero-day vulnerability — named as such since affected organizations have zero days to patch their systems — that allows attackers to remotely run code on vulnerable servers running Log4j, which developers use to keep a record of what’s happening inside an application as it runs. The vulnerability is tracked as [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) (uncovered recently on December 10th) and was given the maximum 10.0 severity rating, meaning attackers can remotely take full control of a vulnerable system over the internet without any interaction from the victim — and it doesn’t require much skill to pull it off.” - from [TechCrunch](https://techcrunch.com/2021/12/13/the-race-is-on-to-patch-log4shell-as-attacks-begin-to-rise/)

Related resources:

- [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228)
- [Wired - The Internet Is on Fire](https://www.wired.com/story/log4j-flaw-hacking-internet/)
- [Log4j: Serious software bug has put the entire internet at risk | New Scientist](https://www.newscientist.com/article/2301331-log4j-software-bug-is-severe-risk-to-the-entire-internet/)

## **Common questions** regarding the Log4j Exploit we have got from our customers

- Does Holistics use Log4j?
- Is Holistics affected by the Log4j Exploit?

## **Our Answer: Holistics is not affected by the exploit**

Most of our technical stack is Ruby, and no other services use Java or the specific vulnerable log4j library version. So **Holistics is not affected by the Vulnerability issue**.

In addition, although this blog post is quite old, it can give you a sense of the core of Holistics [How We Built A Job Queue System with PostgreSQL & Ruby For Our B2B SaaS Application](https://www.holistics.io/blog/how-we-built-a-multi-tenant-job-queue-system-with-postgresql-ruby/).
