You are viewing a plain text version of this content. The canonical link for it is here.
Posted to common-issues@hadoop.apache.org by "Brahma Reddy Battula (Jira)" <ji...@apache.org> on 2020/08/24 13:15:00 UTC

[jira] [Created] (HADOOP-17221) Upgrade log4j-1.2.17 to atlassian ( To Adress: CVE-2019-17571)

Brahma Reddy Battula created HADOOP-17221:
---------------------------------------------

             Summary: Upgrade log4j-1.2.17 to atlassian ( To Adress: CVE-2019-17571)
                 Key: HADOOP-17221
                 URL: https://issues.apache.org/jira/browse/HADOOP-17221
             Project: Hadoop Common
          Issue Type: Bug
            Reporter: Brahma Reddy Battula


Currentlly there are no active release under 1.X in log4j and log4j2 is incompatiable to upgrade (see HADOOP-16206 ) for more details.

But following CVE is reported on log4j 1.2.17..I think,we should consider to update to Atlassian([https://mvnrepository.com/artifact/log4j/log4j/1.2.17-atlassian-0.4]) or redhat versions

[https://nvd.nist.gov/vuln/detail/CVE-2019-17571]



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: common-issues-unsubscribe@hadoop.apache.org
For additional commands, e-mail: common-issues-help@hadoop.apache.org