Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-9283

Upgrade Log4j 2 and exclude Log4j 1.2

    XMLWordPrintableJSON

Details

    Description

      A small number of NiFi components include transitive dependencies on Log4j 1.2 that should be excluded to avoid runtime conflicts with Logback.

      Several extension modules include transitive dependencies on older versions Log4j 2, which have associated vulnerabilities with custom socket-based appender configurations.

      Framework and extension modules should exclude all references to Log4j 1.2, and transitive dependencies on Log4j 2 should be upgraded to the latest version 2.14.1.

      Attachments

        Issue Links

          Activity

            People

              exceptionfactory David Handermann
              exceptionfactory David Handermann
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 20m
                  20m