Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Log4j 1.2 to 2.3.2 #354

Closed
rohan2001 opened this issue Mar 24, 2023 · 9 comments
Closed

Update Log4j 1.2 to 2.3.2 #354

rohan2001 opened this issue Mar 24, 2023 · 9 comments
Assignees

Comments

@rohan2001
Copy link

No description provided.

@rohan2001
Copy link
Author

We see Log4j 1.x is used which is causing tf to be vulnerable. Is there way to mitigate this

@UmmerS
Copy link

UmmerS commented Oct 3, 2023

We see Log4j 1.x is used which is causing tf to be vulnerable. Is there way to mitigate this

@rohan2001 have you got any solution for this issue.

@rohan2001
Copy link
Author

@UmmerS I havent got the solution yet.
Do let me know if there is any alternative available

@UmmerS
Copy link

UmmerS commented Oct 3, 2023

@eric-milles please update log4j for latest version and release new version 14.138.0
Many are facing this issue
Thanks in advance.

eric-milles added a commit that referenced this issue Oct 6, 2023
@eric-milles eric-milles self-assigned this Oct 6, 2023
@UmmerS
Copy link

UmmerS commented Oct 9, 2023

@eric-milles
Thanks for update to log4j-1.2.17.jar
But log4j-1.2.17.jar is also vulnerable need to migrate to Log4j v2

@eric-milles eric-milles changed the title How remove Log4J 1.2.x Jar vulnerability on Team Explorer version 14.137.0 Update Log4j 1.2 to 2.3.2 Oct 9, 2023
@eric-milles
Copy link
Collaborator

@UmmerS It is a work in progress. Log4j 2 is not a drop-in replacement since Team Explorer extends FileAppender and uses DOMConfigurator and PropertyConfigurator. https://logging.apache.org/log4j/2.x/manual/migration.html#limitations-of-the-log4j-1-x-bridge

eric-milles added a commit that referenced this issue Oct 10, 2023
@rohan2001
Copy link
Author

@UmmerS @eric-milles what is the fix. New version released?

@rohan2001
Copy link
Author

@UmmerS @eric-milles Steps to mitigate vulnerability

@eric-milles
Copy link
Collaborator

a release is coming shortly

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants