I was looking for a solution to this issue not only for DSpace 6.x, but another application I use "GeoServer". See this " https://www.geosolutionsgroup.com/blog/geosolutions-lo4shell/" for their solution "log4j-1.2.17-norce.jar" for Log4J and their explanation of the differences between Log4J and Log4J2. I replaced (in place without a rebuild) the Log4J 1.2.17 library on a test server, restarted tomcat and it appeared to work for the small tests I completed. I hope this may help some others.
***Note - I'm NOT affiliated with this organization and use at your own RISK. BW On Wednesday, January 5, 2022 at 12:42:34 PM UTC-6 mount...@gmail.com wrote: > Hello all, > > I'm aware that DSpace 6.x is not going to get a patch that would allow > end-users to upgrade to Log4Jv2, but I was wondering whether anyone else is > likely to be working on this? > > Thanks, > > Sarah > -- All messages to this mailing list should adhere to the Code of Conduct: https://www.lyrasis.org/about/Pages/Code-of-Conduct.aspx --- You received this message because you are subscribed to the Google Groups "DSpace Technical Support" group. To unsubscribe from this group and stop receiving emails from it, send an email to dspace-tech+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/dspace-tech/da8fced8-8ee3-49f8-9618-05d537c4856en%40googlegroups.com.