Is GroundWork Monitor affected by CVE-2021-44228
- Case Study
- Customer News
- GroundWork Support
- Industry Trends
- Partner News
- Press Release
- Product Features
- Product Release
- Tech Tips
- Training
- Uncategorized
Is GroundWork Monitor affected by CVE-2021-44228? GroundWork routinely scans released and supported versions for critical vulnerabilities.
For example, on Friday, December 10th, 2021 we scanned GroundWork Monitor Enterprise Edition (EE) versions 8.2.0 and 8.2.1 for the Log4Shell CVE-2021-44228 zero-day vulnerability. On Monday, December 13th, 2021 we also scanned versions 7.2.1, 8.1.3, 8.2.0 and 8.2.1 using updated signatures that came out over the weekend. Our engineers also hand-reviewed the systems to see if any known exploitable configurations exist. The results indicate that GroundWork Monitor (EE) 7.2.1 is not vulnerable. While there is a vulnerable version of log4j 2.11.1 in a few containers in version 8.x, there is no opportunity to exploit it remotely. So no action is needed to secure any supported GroundWork Monitor system for this vulnerability.
The GroundWork team has reviewed industry analysis of the recent Kaseya VSA incident, and while details are still being revealed, there are some useful take-aways we want to share. In particular, certain aspects of preparedness and indicators of active compromise can be monitored. We also want to talk a little bit about where GroundWork Monitor fits into security monitoring as a whole.
GroundWork Monitor Enterprise version 8.2.0 offers enhancements that build on the capabilities we have mentioned in past blogs. While all the dependencies, parent-child, and service and host dependencies are present as before, we have gone through our notification system and revamped it with an eye to making it easier to get the right alerts to the right people, with the right methods.

GroundWork Monitor offers Parent Child configurations for distributed monitoring, enabling the monitoring of a subset of an infrastructure where Child servers report the state and performance metrics to a central, or “Parent” GroundWork server.