Uploaded image for project: 'Apache Jena'
  1. Apache Jena
  2. JENA-2224

Upgrade to log4j 2.17.0

    XMLWordPrintableJSON

Details

    • Task
    • Status: Closed
    • Major
    • Resolution: Done
    • Jena 4.3.2
    • Jena 4.4.0
    • Cmd line tools, Fuseki
    • None

    Description

      https://nvd.nist.gov/vuln/detail/CVE-2021-45105
      https://logging.apache.org/log4j/2.x/security.html

      This only happens if you change the logging pattern.
      As released Fuseki and command line tools do not use the pattern feature involved in CVE-2021-45105.

      Attachments

        Issue Links

          Activity

            People

              andy Andy Seaborne
              andy Andy Seaborne
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: