Uploaded image for project: 'AMQ Streams'
  1. AMQ Streams
  2. ENTMQST-3572

Rebuild log4j 1.2.17 with CVE fixes

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Won't Do
    • Icon: Major Major
    • None
    • None
    • None
    • None
    • False
    • False
    • ProdSec decided that we do not need to patch the log4j 1 CVE.

      Log4j 1.2.17 needs to be rebuilt without JMSAppender (CVE-2021-4104), SocketServer (CVE-2019-17571) and SMTPAppender (CVE-2020-9488). Details on this GH thread.

      The original 1.2.17 build is so old that is it not on PNC. It was originally done in BREW.

      A new build will need to be set up in PNC. The orginal source code can be found at: https://logging.apache.org/log4j/1.2/source-repository.html

            tom.n.cooper Thomas Cooper (Inactive)
            tom.n.cooper Thomas Cooper (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: