[jira] [Commented] (TIKA-3019) [9.8] [CVE-2019-17571] [tika-app] [1.23]

2020-01-15 Thread Konstantin Gribov (Jira)
[ https://issues.apache.org/jira/browse/TIKA-3019?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17016096#comment-17016096 ] Konstantin Gribov commented on TIKA-3019: - [~rgoers], yes, I mentioned {{log4j1.compatibility}}

[jira] [Commented] (TIKA-3019) [9.8] [CVE-2019-17571] [tika-app] [1.23]

2020-01-14 Thread Ralph Goers (Jira)
[ https://issues.apache.org/jira/browse/TIKA-3019?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17015394#comment-17015394 ] Ralph Goers commented on TIKA-3019: --- FWIW - Log4j 2.13.0 includes experimental support for Log4j 1.2

[jira] [Commented] (TIKA-3019) [9.8] [CVE-2019-17571] [tika-app] [1.23]

2020-01-10 Thread Konstantin Gribov (Jira)
[ https://issues.apache.org/jira/browse/TIKA-3019?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17013000#comment-17013000 ] Konstantin Gribov commented on TIKA-3019: - [~tallison], there seems to be actually twofold issue

[jira] [Commented] (TIKA-3019) [9.8] [CVE-2019-17571] [tika-app] [1.23]

2020-01-08 Thread Tim Allison (Jira)
[ https://issues.apache.org/jira/browse/TIKA-3019?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17010973#comment-17010973 ] Tim Allison commented on TIKA-3019: --- Got it.  That was my understanding as well.  If we remove log4jx 1x

[jira] [Commented] (TIKA-3019) [9.8] [CVE-2019-17571] [tika-app] [1.23]

2020-01-07 Thread Kenneth William Krugler (Jira)
[ https://issues.apache.org/jira/browse/TIKA-3019?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17010262#comment-17010262 ] Kenneth William Krugler commented on TIKA-3019: --- Hi [~tallison] - if we're explicitly using

[jira] [Commented] (TIKA-3019) [9.8] [CVE-2019-17571] [tika-app] [1.23]

2020-01-06 Thread Tim Allison (Jira)
[ https://issues.apache.org/jira/browse/TIKA-3019?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17009148#comment-17009148 ] Tim Allison commented on TIKA-3019: --- IIUC, the fix for this would be to swap out slf4j-log4j12 for