Log4j vulnerability

113 views
Skip to first unread message

Kaz C

unread,
Dec 12, 2021, 7:37:18 PM12/12/21
to BrowserMob Proxy
Hi,

Regarding the log4j vulnerability identified recently, is Browsermob Proxy affected?

Haven't been able to find out if it is or what version of log4j it is running.

Thanks.

⇜Krishnan Mahadevan⇝

unread,
Dec 13, 2021, 12:53:52 AM12/13/21
to browserm...@googlegroups.com
The version information is available in the pom file (2.9.0)



Thanks & Regards
Krishnan Mahadevan

"All the desirable things in life are either illegal, expensive, fattening or in love with someone else!"
My Scribblings @ http://wakened-cognition.blogspot.com/
My Technical Scribblings @ https://rationaleemotions.com/


--

---
You received this message because you are subscribed to the Google Groups "BrowserMob Proxy" group.
To unsubscribe from this group and stop receiving emails from it, send an email to browsermob-pro...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/browsermob-proxy/f45c29b3-82c9-4fc4-92ff-fc9e3a3b57bdn%40googlegroups.com.

Kaz C

unread,
Dec 13, 2021, 1:44:22 AM12/13/21
to BrowserMob Proxy
Thanks Krishnan. I see it's using an affected version of log4j.

⇜Krishnan Mahadevan⇝

unread,
Dec 13, 2021, 1:49:24 AM12/13/21
to browserm...@googlegroups.com
You can always add an exclusion of that version and then explicitly add a new version.

Additionally, I also read that you can add a JVM argument to disable that behaviour.


Thanks & Regards
Krishnan Mahadevan

"All the desirable things in life are either illegal, expensive, fattening or in love with someone else!"
My Scribblings @ http://wakened-cognition.blogspot.com/
My Technical Scribblings @ https://rationaleemotions.com/

Reply all
Reply to author
Forward
0 new messages