Karaf 4.2.14 has been released, this version should include the fix for the log4j issue, that has been mitigated in ONOS with a couple of custom changes:
Karaf runtime 4.2.14 has been released! December 24, 2021Apache Karaf runtime 4.2.14 is a release on the 4.2.x series. It provides updates, fixes, improvements, especially:
- upgrade to Pax Logging 1.11.12, with log4j 2.17.0 fixing CVE-2021-45105 and logback 1.2.9 fixing CVE-2021-42550
Should we update Karaf in ONOS to this new version?
In case we want to update, I'm happy to help and learn the process for updating Karaf!
Daniele