Details
-
Task
-
Status: Resolved
-
Major
-
Resolution: Duplicate
-
4.2.12, 4.3.3
-
None
-
None
Description
Logback CVE-2021-42550 along the lines of Log4Shell.
logback fixed in v1.2.9
Notes:
- Karaf does not install logback bundle from pax-logging by default
- there is no feature to install pax-logging-logback
- Users must manually enable logback
Attachments
Issue Links
- is duplicated by
-
KARAF-7300 Upgrade to Pax Logging 2.0.13
- Resolved