irods-contrib / metalnx-web

Metalnx Web Application
https://metalnx.github.io/
BSD 3-Clause "New" or "Revised" License
36 stars 36 forks source link

log4J vulnerabilty #296

Closed kript closed 2 years ago

kript commented 2 years ago

Hi folks,

Can I ask if this project uses log4J? If so, it might need a version bump; https://www.lunasec.io/docs/blog/log4j-zero-day/

cheers

John

trel commented 2 years ago

Doesn't affect this project for now - still using log4j 1.x

https://github.com/irods-contrib/metalnx-web/blob/dcfcacb003b178be4c0ff609bfd64b152bc242d0/src/pom.xml#L287-L292

Closing.

When we bump to log4j 2.x, we'll get the latest version (v2.15.0+) and be immune to this issue.