OneBusAway / onebusaway-application-modules

The core OneBusAway application suite.
https://github.com/OneBusAway/onebusaway-application-modules/wiki
Other
207 stars 133 forks source link

Log4J vulnerability (CVE-2021-44228) #300

Closed ethanpooley closed 2 years ago

ethanpooley commented 2 years ago

Could we get a statement from maintainers about CVE-2021-44228? It's been hard for me to tell whether OneBusAway is vulnerable and, if so, what should be done about it. My current, possibly quite flawed, understanding:

Consquently, it would be great to hear from some maintainers about their thoughts and plans.

sheldonabrown commented 2 years ago

Correct, OneBusAway is still using Log4j 1.2, so appears to be immune.

Please do your own research and make your own decisions, but as I understand the vulnerability it does not affect OBA.