Log4j/Log4Shell vulnerability

86 views
Skip to first unread message

lasp...@gmail.com

unread,
Dec 14, 2021, 6:33:36 PM12/14/21
to psi-prob...@googlegroups.com

Does PSI-Probe utilize Log4J and/or has it been tested and patched for the new Log4Shell attack vulnerability?

 

Log4Shell info:

https://www.trendmicro.com/en_us/research/21/l/patch-now-apache-log4j-vulnerability-called-log4shell-being-acti.html

 


Virus-free. www.avast.com

haze...@gmail.com

unread,
Dec 22, 2021, 9:23:12 PM12/22/21
to psi-probe-discuss
Not affected.  The runtime does not include log4j2.  The build uses it only so that users of log4j2 can retrieve their logs within the product.  Look in the WAR/lib to confirm.  The project itself uses slf4j/logback for logging needs.  And any/all build aretifacts are constantly updated on master on the project including every patch log4j pushed.
Reply all
Reply to author
Forward
Message has been deleted
0 new messages