Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-9505

Upgrade Log4j 2 to 2.17.0

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Minor
    • Resolution: Fixed
    • None
    • 1.16.0, 1.15.2
    • None
    • None

    Description

      Log4j 2 version 2.17.0 addresses a potential vulnerability in non-standard logging configurations using Thread Context Map lookup capabilities, described in CVE-2021-45105.

      Although NiFi does not use Log4j 2 for runtime logging, upgrading to version 2.17.0 avoids potential references to older versions in external components.

      Attachments

        Issue Links

          Activity

            People

              exceptionfactory David Handermann
              exceptionfactory David Handermann
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: