Video | Tableau | Tool strategy | Industry trends

LOG4J2 fix for All Tableau products - (Updated 15th December) see description for more

If you're on an older Tableau build, the Log4j2 vulnerability means you need to update or uninstall it right now.

Part ofBehind The Scenes
  • Every Tableau product is affected by the Log4j2 remote code execution vulnerability, including Desktop, Public, Reader, Online, Server and Prep Builder across Windows, Mac and Linux.
  • You must be on the build released on 15th December 2021 to be patched, not just on 2020.4 generally; versions 2020.3 and older are past end of maintenance and will not be patched.
  • Tableau Prep treats every release as a patch, so your only fix is to upgrade to the latest version (2021.4.1), not stay on an older build.
  • Tableau's knowledge base offers manual mitigation steps, but they need admin rights and are hard to maintain, so updating is by far the easiest route.
  • Uninstall old versions entirely; leaving them on your laptop keeps you exposed, as a targeted workbook could compromise your machine and reach your server and data.

New issue discovered on 15th December: https://www.praetorian.com/blog/log4j-2-15-0-stills-allows-for-exfiltration-of-sensitive-data/ Tableau KB on the issue and patching the issue: https://kb.tableau.com/articles/issue/Apache-Log4j2-vulnerability-Log4shell Salesforce products affected: https://help.salesforce.com/s/articleView?id=000363736&type=1

0:00 Intro 2:30 Upgrade to fix for 2020.4 or newer 3:50 Take note if you use Prep 5:40 If you cant upgrade, Option 2 to fix