EnMasseProject / enmasse

EnMasse - Self-service messaging on Kubernetes and OpenShift
https://enmasseproject.github.io
Apache License 2.0
189 stars 89 forks source link

Is enmasse related to log4j2 vuln? (CVE-2021-44228) #5317

Closed aaron0609 closed 1 year ago

aaron0609 commented 2 years ago

Hi, I'm using enmasse in production environment, would like to know if the log4j2 vuln exists in our enmasse?

k-wall commented 2 years ago

No, log4j2 is not used by EnMasse. EnMasse's java components use Logback. Apache Dispatch Router is not Java, and Artemis uses the JBoss Logging framework https://activemq.apache.org/components/artemis/documentation/latest/logging.html