Uploaded image for project: 'AMQ Streams'
  1. AMQ Streams
  2. ENTMQST-3667

Productise Log4j 1.2.17 with CVE fixes

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Won't Do
    • Icon: Major Major
    • 2.0.1.GA
    • None
    • None
    • None

      PNC Build: https://orch.psi.redhat.com/pnc-web/#/projects/1109

      Log4j 1.2.17 needs to be rebuilt without JMSAppender (CVE-2021-4104), SocketServer (CVE-2019-17571) and SMTPAppender (CVE-2020-9488). Details on this GH thread.

      The original 1.2.17 build is so old that is it not on PNC. It was originally done in BREW.

              rh-ee-tcooper Thomas Cooper
              rh-ee-tcooper Thomas Cooper
              Lukas Kral Lukas Kral
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: