Spica Technologies Statement: Platform not affected by “Log4Shell”

December 14, 2021
Gemma Worgan

You may have recently seen in the news information relating to a potentially very serious security vulnerability that will likely affect a broad range of cloud-based SaaS offerings and services. The exploit was disclosed on December 9th, and could potentially allow an attacker to execute code on a remote server. The vulnerability was found within a popular Java-based logging package known as Log4j. Given the widespread use of Java in cloud-based systems, and the widespread use of Log4j as a logging framework, the vulnerability is considered one of the most serious in recent times.

You can read more about the exploit and its potential impacts here: https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/12/log4j-zero-day-log4shell-arrives-just-in-time-to-ruin-your-weekend/

Spica Status

As soon as Spica became aware of the vulnerability, we took steps to protect our platform and most importantly our customer data. 

To be clear, we do not believe that Spica’s GemEx platform or the Luna app were vulnerable to this exploit at any point in time.

Nevertheless, we took steps to protect ourselves and conduct an investigation:

  • On the 10th December Spica’s hosting partner, Amazon Web Services (AWS), released an  update to their Web Application Firewall (WAF) which is used to safeguard all of Spica’s cloud resources. The update added new rules to the firewall to prevent requests that contain the commonly used Log4j headers from reaching GemEx instances, and Spica’s WAF infrastructure was updated automatically.
  • Spica has conducted a review of all cloud application source code, verifying that none of the affected Log4j libraries are being used in any of our products.
  • We have passed on information relating to the vulnerability to our IOT vendors and have asked them to confirm whether they are affected.

To reiterate, Spica is not directly affected by the CVE-2021-44228 exploit and we will continue to gather information from our suppliers to determine whether they have been affected. We strongly encourage customers who manage environments containing Log4j to check to see if they are affected and take the necessary action.

Introducing GemEx for Outlook

Introducing GemEx for Outlook

Introducing GemEx for Outlook, our latest innovation designed to bring a new level of efficiency and convenience to managing your office bookings within the comfort of the Outlook interface. Seamlessly search, create, and manage room bookings while effortlessly adding...

read more
Spica at WORKTECH Financial London 2024

Spica at WORKTECH Financial London 2024

Last Friday, March 15th, Spica's Business Development Manager, Paul Mundy, attended WORKTECH Financial London 2024. The event was hosted at none other than Spica's esteemed client, M&G's headquarters in the iconic 10 Fenchurch Avenue building. Spica was a bespoke...

read more
Inspire Inclusion in the Tech Sector with Spica

Inspire Inclusion in the Tech Sector with Spica

March 8th marks International Women's Day, a day to celebrate the achievements of women worldwide and advocate for gender equality. This year's theme is inspire inclusion. At Spica, we are committed to fostering a diverse and inclusive workplace, particularly within...

read more
Workplace trends in 2024: What to expect

Workplace trends in 2024: What to expect

As we step into 2024, big changes are happening in workplaces everywhere. From making sure our online spaces are safe to using more smart technology, the future is full of exciting possibilities and some challenges too. Keeping Our Workplaces Safe Online In 2024,...

read more