Open FlUxIuS opened 2 years ago
There is 2.17.1 already in https://github.com/SwitchEV/RISE-V2G/blob/master/RISE-V2G-Shared/pom.xml
<dependency>
<groupId>org.apache.logging.log4j</groupId>
<artifactId>log4j-api</artifactId>
<version>2.17.1</version>
</dependency>
<dependency>
<groupId>org.apache.logging.log4j</groupId>
<artifactId>log4j-core</artifactId>
<version>2.17.1</version>
</dependency>
Need to update the dependency version, or to filter by using 'formatMsgNoLookups'.
This vulnerability isn't strickly easy to exploit, but an EVCC can send this encoded payload to the EVSE, and trigger the bug during even in the first
supportedAppProtocolReq
state: