Security advisories
Vulnerability and incident notices for Informer, with the steps to check whether you are affected and how to remediate. These are point-in-time records of specific incidents; each one names the versions and dates it applies to.
If you are unsure whether an advisory applies to your deployment, contact Support at i5support@entrinsik.com.
In this section
| Article | In one line |
|---|---|
| Axios compromised dependency (on-premise) | The 2025.2.12 Axios supply-chain incident for self-hosted servers: how to tell if you are affected and what to do. |
| Axios compromised dependency (Informer Cloud) | The same incident as it relates to Informer Cloud, and the recommended precautions. |
| Axios incident root cause analysis | Where to get the detailed technical write-up of the 2025.2.12 Axios incident. |
| Log4j vulnerabilities (CVE-2021-44228, CVE-2021-45046) | Mitigating the 2021 Log4j vulnerabilities in the Elasticsearch that ships with Informer. |
Where do I look when...
| You want to... | Start here |
|---|---|
| Check a self-hosted server for the Axios incident | Axios compromised dependency (on-premise) |
| Understand the Cloud-side impact of the Axios incident | Axios compromised dependency (Informer Cloud) |
| Read the full technical analysis | Axios incident root cause analysis |
| Mitigate the 2021 Log4j vulnerabilities | Log4j vulnerabilities |