Uploaded image for project: 'Phoenix'
  1. Phoenix
  2. PHOENIX-7169

Phoenix-connectors should not depend on log4j:log4j

    XMLWordPrintableJSON

Details

    Description

      Apache phoenix-connectors has log4j:log4j:1.2.17 as direct dependency (See https://github.com/apache/phoenix-connectors/blob/master/pom.xml#L830), which is vulnerable: https://security.snyk.io/package/maven/log4j:log4j/1.2.17

      In my org, this dependency is not even allowed to be downloaded and hence I can't even build the code in it's current state.

      With this ticket I plan to completely remove it from the project.

      CC: stoty 

      Attachments

        Issue Links

          Activity

            People

              nihaljain.cs Nihal Jain
              nihaljain.cs Nihal Jain
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated: