[GitHub] [logging-log4j2] peturthors commented on pull request #608: Restrict LDAP access via JNDI

2021-12-10 Thread GitBox
peturthors commented on pull request #608: URL: https://github.com/apache/logging-log4j2/pull/608#issuecomment-991139464 > Can't find much info about it. grep-ing through the source code for jdk-11.0.1 we get `src/java.naming/com/sun/jndi/ldap/VersionHelper.java: Privileg

[GitHub] [logging-log4j2] peturthors commented on pull request #608: Restrict LDAP access via JNDI

2021-12-10 Thread GitBox
peturthors commented on pull request #608: URL: https://github.com/apache/logging-log4j2/pull/608#issuecomment-990879257 Hi there. Would setting the JVM property `com.sun.jndi.ldap.object.trustURLCodebase = false` mitigate this ? Thanks. -- This is an automated message from the Apa