Re: [mapserver-users] security problem?

2021-12-14 Thread Rahkonen Jukka (MML)
Hi,

Of course people may use log4j2 in their own code but  Mapserver project does 
not deliver log4j nor is it used in any of the examples 
https://github.com/MapServer/MapServer/tree/main/mapscript/java.

-Jukka Rahkonen-

-Alkuperäinen viesti-
Lähettäjä: Bjørn Ove Grøtan  
Lähetetty: tiistai 14. joulukuuta 2021 17.08
Vastaanottaja: Rahkonen Jukka (MML) 
Kopio: Zimmer Rene ; 
'mapserver-users@lists.osgeo.org' 
Aihe: Re: [mapserver-users] security problem?

Uhm - guess not many are using the Mapscript Java-binding then? (I don't, so 
haven't tested) https://mapserver.org/ogc/mapscript.html

But as Jukka said, Mapserver in itself is not written in Java.
If you are using Mapscript w/Java bindings, you have to check for yourself what 
you do in your own code.

According to https://trac.osgeo.org/mapserver/wiki/JavaMapscriptUsing
commons-logging is being used, not log4j - if you are indeed using 
Mapscript-Java.

-Bjørn 

Rahkonen Jukka (MML):
> Hi,
> 
> Log4j is a Java library, Mapserver is not Java. You can feel safe with this 
> issue.
> 
> -Jukka Rahkonen-
> 
> Lähettäjä: MapServer-users  
> Puolesta Zimmer Rene
> Lähetetty: tiistai 14. joulukuuta 2021 15.36
> Vastaanottaja: 'mapserver-users@lists.osgeo.org' 
> 
> Aihe: [mapserver-users] security problem?
> 
> Hello everybody,
> 
> when using Mapserver, is there also a security problem with log4j?
> 
> Is it used?
> 
> If so, how can the gap be closed?
> 
> 
> Thanks,
> 
> Rene
> 
> 
> 
> 
> --
> 
> This email was Anti Virus checked by Astaro Security Gateway.
> 
> 
> 
> Geprüft und getestet

> ___
> MapServer-users mailing list
> MapServer-users@lists.osgeo.org
> https://lists.osgeo.org/mailman/listinfo/mapserver-users
___
MapServer-users mailing list
MapServer-users@lists.osgeo.org
https://lists.osgeo.org/mailman/listinfo/mapserver-users


Re: [mapserver-users] security problem?

2021-12-14 Thread Bjørn Ove Grøtan
Uhm - guess not many are using the Mapscript Java-binding then? (I don't, so 
haven't tested)
https://mapserver.org/ogc/mapscript.html

But as Jukka said, Mapserver in itself is not written in Java.
If you are using Mapscript w/Java bindings, you have to check for yourself 
what you do in your own code.

According to https://trac.osgeo.org/mapserver/wiki/JavaMapscriptUsing
commons-logging is being used, not log4j - if you are indeed using 
Mapscript-Java.

-Bjørn 

Rahkonen Jukka (MML):
> Hi,
> 
> Log4j is a Java library, Mapserver is not Java. You can feel safe with this 
> issue.
> 
> -Jukka Rahkonen-
> 
> Lähettäjä: MapServer-users  Puolesta 
> Zimmer Rene
> Lähetetty: tiistai 14. joulukuuta 2021 15.36
> Vastaanottaja: 'mapserver-users@lists.osgeo.org' 
> 
> Aihe: [mapserver-users] security problem?
> 
> Hello everybody,
> 
> when using Mapserver, is there also a security problem with log4j?
> 
> Is it used?
> 
> If so, how can the gap be closed?
> 
> 
> Thanks,
> 
> Rene
> 
> 
> 
> 
> --
> 
> This email was Anti Virus checked by Astaro Security Gateway.
> 
> 
> 
> Geprüft und getestet

> ___
> MapServer-users mailing list
> MapServer-users@lists.osgeo.org
> https://lists.osgeo.org/mailman/listinfo/mapserver-users
___
MapServer-users mailing list
MapServer-users@lists.osgeo.org
https://lists.osgeo.org/mailman/listinfo/mapserver-users


Re: [mapserver-users] security problem?

2021-12-14 Thread Rahkonen Jukka (MML)
Hi,

Log4j is a Java library, Mapserver is not Java. You can feel safe with this 
issue.

-Jukka Rahkonen-

Lähettäjä: MapServer-users  Puolesta 
Zimmer Rene
Lähetetty: tiistai 14. joulukuuta 2021 15.36
Vastaanottaja: 'mapserver-users@lists.osgeo.org' 

Aihe: [mapserver-users] security problem?

Hello everybody,

when using Mapserver, is there also a security problem with log4j?

Is it used?

If so, how can the gap be closed?


Thanks,

Rene




--

This email was Anti Virus checked by Astaro Security Gateway.



Geprüft und getestet
___
MapServer-users mailing list
MapServer-users@lists.osgeo.org
https://lists.osgeo.org/mailman/listinfo/mapserver-users


[mapserver-users] security problem?

2021-12-14 Thread Zimmer Rene
Hello everybody,

when using Mapserver, is there also a security problem with log4j?

Is it used?

If so, how can the gap be closed?


Thanks,

Rene


-- 
This email was Anti Virus checked by Astaro Security Gateway. 

Geprüft und getestet
___
MapServer-users mailing list
MapServer-users@lists.osgeo.org
https://lists.osgeo.org/mailman/listinfo/mapserver-users