---
title: "Flow customer statement on log4j"
canonical: "https://support.appfire.com/space/FD/1802338327/Flow%20customer%20statement%20on%20log4j"
format: markdown
---
## Flow Cloud statement

The Flow team has remediated all known instances of log4j as prescribed by the [NCSC guidelines (external site, opens in new tab)](https://www.ncsc.gov.uk/news/apache-log4j-vulnerability). In addition, we have investigated our third-party commercial dependencies, each of which has been remediated or we’ve deemed to have no impact to Flow or Flow customers. We are also following NCSC guidelines for compromise detection and mitigation, and have identified zero successful exploits. We are continuing to follow the NCSC guidelines which includes updating to the latest version and as their guidance is updated, we are taking immediate action to remediate.

## Flow Enterprise Server statement

The Flow teams have identified instances of log4j and are actively remediating all risks as prescribed by the [NCSC guidelines (external site, opens in new tab)](https://www.ncsc.gov.uk/news/apache-log4j-vulnerability). For the Flow Enterprise Server product, customers can remediate their running system through JVM configurations available on the management console. 

Additionally, we have released an upgrade that will mitigate all known product risks, including start-up modules. We recommend that all customers perform an upgrade at their earliest, reasonable convenience.

Once customers are on 2021.3.1-2 or higher, the JVM remediation is no longer required. We will continue to address new vulnerabilities with new releases as necessary.