Hi everyone,
While deploying i2b2 version 1.8.3, our Tenable vulnerability scanner flagged an exploitable Log4j issue within i2b2.war.
Scanner Findings:
Installed Version: 2.24.3
Fixed Version: 2.25.3
Location inside i2b2.war:
WEB-INF/classes/log4j2.xml
WEB-INF/lib/log4j-api-2.24.3.jar
WEB-INF/lib/log4j-core-2.24.3.jar
WEB-INF/lib/log4j-jcl-2.24.3.jar
Has anyone else encountered this finding during a 1.8.3 installation? What is the recommended approach for updating these nested Log4j JARs inside the WAR file without breaking dependencies?
Thanks for any guidance!
The information in this e-mail is intended only for the person to whom it is addressed. If you believe this e-mail was sent to you in error and the e-mail contains patient information, please contact the Mass General Brigham Compliance HelpLine at https://www.massgeneralbrigham.org/complianceline .
Please note that this e-mail is not secure (encrypted). If you do not wish to continue communication over unencrypted e-mail, please notify the sender of this message immediately. Continuing to send or respond to e-mail after receiving this message means you understand and accept this risk and wish to continue to communicate over unencrypted e-mail.
You received this message because you are subscribed to a topic in the Google Groups "i2b2 Install Help" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/i2b2-install-help/nXPfssPYH7k/unsubscribe.
To unsubscribe from this group and all its topics, send an email to i2b2-install-h...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/i2b2-install-help/BYAPR04MB4390D7660992A5EC48A86B04B3CC2%40BYAPR04MB4390.namprd04.prod.outlook.com.