-
Notifications
You must be signed in to change notification settings - Fork 950
[1.5.x] log4j 2.16.0 #6749
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[1.5.x] log4j 2.16.0 #6749
Conversation
Hi @augi, Thank you for your contribution! We really value the time you've taken to put this together. Before we proceed with reviewing this pull request, please sign the Lightbend Contributors License Agreement: |
Are you sure? I dont see anything in https://logging.apache.org/log4j/2.x/changes-report.html#a2.16.0 that suggests that... |
@augi Thanks for the contribution.
Could you clarify this statement please? https://lists.apache.org/thread/d6v4r6nosxysyq9rvnr779336yf0woz4 says that it's more hardened but it doesn't say that 2.15.0 is "vulnerable" in the same way the 2.x releases prior to 2.15.0 was. |
Hello, quoting from this ticket:
So they decided to remove default JDNI support by default as it has significant security issue. |
Thanks. Looks like https://logging.apache.org/log4j/2.x/security.html says
|
Waiting the new release... finishing this endless log4j curse. |
Has this been deployed? I have been using version 1.5.6 but still, it is fetching the 2.15.0 log4j version. |
The update to |
Okay and Thanks |
The 2.15.0 version is still vulnerable.