electerious / Ackee

Self-hosted, Node.js based analytics tool for those who care about privacy.
https://ackee.electerious.com
MIT License
4.2k stars 351 forks source link

LOG4J vulnerabilities? #311

Closed dennisheiden closed 2 years ago

dennisheiden commented 2 years ago

Our server provider told us, that their LOG4J scan said, that the ackee docker image might be vulnerable. I don't know why this should be the case here, but can anybody here confirm that there is no such LOG4J-vulnerability?

electerious commented 2 years ago

This seemed unlikely to me since Ackee doesn't use JAVA libraries, but I ran docker scan to be sure and everything is fine:

✓ Tested 16 dependencies for known issues, no vulnerable paths found.