qos-ch / reload4j

reload4j is a drop-in replacement for log4j 1.2.17
Apache License 2.0
148 stars 22 forks source link

possible XXE vector #53

Closed ceki closed 2 years ago

ceki commented 2 years ago

A new XXE vector has been reported.

Based on this report a new reload4j version will be released shorty.

More details to follow.

ceki commented 2 years ago

Fixed in commit 3a86b8e5b