CrushFTP is not affected by cve-2021-44228 (Log4Shell). The only Log4j we had in our CrushFTP products was v 1.2.17...which is before the vulnerable code was added to Log4j. So this vulnerability has no effect on CrushFTP. Additionally don't use log4j for logging either, its just part of CrushFTP for other libraries that need it in place. So this issue is doubly irrelevant for CrushFTP.

CrushFTP 10.3.0 (Released on June 8th 2022) : Change Log

Upgrading from v7, v8 or v9 to v10? Read this short upgrade guide.

