elastic / ecs-logging-java

https://www.elastic.co/guide/en/ecs-logging/java/current/intro.html
Apache License 2.0
141 stars 75 forks source link

Update to logback 1.28 #158

Closed rdifrango closed 2 years ago

rdifrango commented 2 years ago

In response to the log4j issue, the logback team has released 1.28 to cover a more unlikely scenario where a similiar exploit can happen as described here to quote:

However, logback may make JNDI calls from within its configuration file. This was recently reported in LOGBACK-1591 as a vulnerability of lesser severity. In response, we have released logback version 1.2.8. Please upgrade.