Description
log4j 1.2.17 has the following vulnerabilities:
- CVE-2022-23302: JMSSink
- CVE-2022-23305 : JDBCAppender
- CVE-2022-23307 : Chainsaw
We should exclude the related classes from the generated jars.
Attachments
Issue Links
- relates to
-
RATIS-1499 Is Apache Ratis 2.2.0 affected by the high-risk vulnerability of the log4j 1.X series?
- Resolved
- links to