You are viewing a plain text version of this content. The canonical link for it is here.
Posted to jira@kafka.apache.org by GitBox <gi...@apache.org> on 2022/02/22 08:03:27 UTC

[GitHub] [kafka] rgoers commented on pull request #7898: KAFKA-9366: Change log4j dependency into log4j2

rgoers commented on pull request #7898:
URL: https://github.com/apache/kafka/pull/7898#issuecomment-1047522217


   @Indupa Please note that the Apache Logging Services project continues to receive security vulnerability reports against Log4j 1.x. It is not typical to file CVE's against an EOL'd project. We recently did, however as we were made aware that a fork of Log4j 1 claimed to have fixed all the security issues. We may file more but Log4j 1 is not a high priority so I cannot say when more might be forthcoming. In addition to the security issues there are several serious bugs that will never be fixed.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: jira-unsubscribe@kafka.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org