opsgenie / opsgenie-configuration-backup

Backup your OpsGenie account's configuration and restore it later
https://opsgenie.com
Apache License 2.0
28 stars 26 forks source link

Dependency to log4j 2.9.1 #48

Closed cite closed 2 years ago

cite commented 2 years ago

Hi everyone,

in light of the recent log4shell attack, we were wondering if it wouldn't be better to bump the version of log4j. We fear the configuration export might be vulnerable to malformed names in e.g. Overrides.

If that's a valid concern, is it enough to simply bump the log4j version?

Cheers, Stefan