Uploaded image for project: 'AMQ Streams'
  1. AMQ Streams
  2. ENTMQST-3572

Rebuild log4j 1.2.17 with CVE fixes

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Won't Do
    • Icon: Major Major
    • None
    • None
    • None
    • None
    • False
    • False
    • ProdSec decided that we do not need to patch the log4j 1 CVE.

      Log4j 1.2.17 needs to be rebuilt without JMSAppender (CVE-2021-4104), SocketServer (CVE-2019-17571) and SMTPAppender (CVE-2020-9488). Details on this GH thread.

      The original 1.2.17 build is so old that is it not on PNC. It was originally done in BREW.

      A new build will need to be set up in PNC. The orginal source code can be found at: https://logging.apache.org/log4j/1.2/source-repository.html

              rh-ee-tcooper Thomas Cooper
              rh-ee-tcooper Thomas Cooper
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: