Page 1 of 1

Java Log4j vulnerability

PostPosted: Dec 15th, '21, 23:30
by brm
Hi all. Should we be worried about the java log4j vulnerability? Any suggestions for Mageia users about this?

I came across this script and include it for others. Use at your own risk. It will search your system for log4j files.
https://raw.githubusercontent.com/rubo77/log4j . . . (snip}

Disclaimer.
Mid Level Linux user here.
I am not a developer.

Feel free to move this post to a better forum if necessary.

Re: Java Log4j vulnerability

PostPosted: Dec 15th, '21, 23:32
by sturmvogel
For such stuff it is always recommended to follow our bugtracker. The latest secured log4j version 2.16 is already in our testing repo and QA process.
https://bugs.mageia.org/show_bug.cgi?id=29766

Re: Java Log4j vulnerability

PostPosted: Dec 15th, '21, 23:40
by brm
I look forward to this fix coming through our updates.
Thanks

Re: Java Log4j vulnerability

PostPosted: Dec 15th, '21, 23:45
by doktor5000
brm wrote:Hi all. Should we be worried about the java log4j vulnerability? Any suggestions for Mageia users about this?

Nothing specific for Mageia, as this basically affects nearly everyone in some kind of way, even when it's not directly on your own Mageia install.
BTW your link seems to be incomplete, probably this one: https://github.com/rubo77/log4j_checker_beta

If you're not a developer, to understand the issue at hand and some context information and also some hints on how to avoid or fix this, have a look at e.g. https://www.youtube.com/watch?v=7qoPDq41xhQ

Re: Java Log4j vulnerability

PostPosted: Dec 22nd, '21, 12:47
by papoteur
2.17 release of log4j is now available as update