Skip to main content

Security advisories

Vulnerability and incident notices for Informer, with the steps to check whether you are affected and how to remediate. These are point-in-time records of specific incidents; each one names the versions and dates it applies to.

If you are unsure whether an advisory applies to your deployment, contact Support at i5support@entrinsik.com.

In this section

ArticleIn one line
Axios compromised dependency (on-premise)The 2025.2.12 Axios supply-chain incident for self-hosted servers: how to tell if you are affected and what to do.
Axios compromised dependency (Informer Cloud)The same incident as it relates to Informer Cloud, and the recommended precautions.
Axios incident root cause analysisWhere to get the detailed technical write-up of the 2025.2.12 Axios incident.
Log4j vulnerabilities (CVE-2021-44228, CVE-2021-45046)Mitigating the 2021 Log4j vulnerabilities in the Elasticsearch that ships with Informer.

Where do I look when...

You want to...Start here
Check a self-hosted server for the Axios incidentAxios compromised dependency (on-premise)
Understand the Cloud-side impact of the Axios incidentAxios compromised dependency (Informer Cloud)
Read the full technical analysisAxios incident root cause analysis
Mitigate the 2021 Log4j vulnerabilitiesLog4j vulnerabilities