Re: CVE-2021-44228 - Log4j2 vulnerability

2022-02-20 Thread Francis Conroy
k 1.14.3 is in preparation and this >>>>> hasn't started yet for Flink 1.13.6. Flink 1.12.8 release will be >>>>> planned after this? If there is no current plan, could you please let us >>>>> know what will be the regular

Re: CVE-2021-44228 - Log4j2 vulnerability

2022-02-20 Thread Surendra Lalwani
21-44228 - Log4j2 vulnerability >>>> >>>> >>>> >>>> Hi Suchithra, >>>> >>>> >>>> >>>> there is currently no plan on doing another 1.12 release >>>> >>>> >>>&g

Re: CVE-2021-44228 - Log4j2 vulnerability

2022-02-03 Thread Martijn Visser
t;>> >>> >>> *From:* David Morávek >>> *Sent:* Sunday, January 9, 2022 12:11 AM >>> *To:* V N, Suchithra (Nokia - IN/Bangalore) >>> *Cc:* Chesnay Schepler ; Martijn Visser < >>> mart...@ververica.com>; Michael Guterl ; Parag >>

Re: CVE-2021-44228 - Log4j2 vulnerability

2022-02-03 Thread Surendra Lalwani
* Chesnay Schepler ; Martijn Visser < >> mart...@ververica.com>; Michael Guterl ; Parag Somani >> ; patrick.eif...@sony.com; Richard Deurwaarder < >> rich...@xeli.eu>; User ; subharaj.ma...@gmail.com; >> swamy.haj...@gmail.com >> *Subject:* Re: CVE-2021-442

Re: CVE-2021-44228 - Log4j2 vulnerability

2022-01-09 Thread David Morávek
tijn Visser < > mart...@ververica.com>; Michael Guterl ; Parag Somani < > somanipa...@gmail.com>; patrick.eif...@sony.com; Richard Deurwaarder < > rich...@xeli.eu>; User ; subharaj.ma...@gmail.com; > swamy.haj...@gmail.com > *Subject:* Re: CVE-2021-44228 - Log4j

RE: CVE-2021-44228 - Log4j2 vulnerability

2022-01-09 Thread V N, Suchithra (Nokia - IN/Bangalore)
: Re: CVE-2021-44228 - Log4j2 vulnerability Hi Suchithra, there is currently no plan on doing another 1.12 release D. On Sat 8. 1. 2022 at 18:02, V N, Suchithra (Nokia - IN/Bangalore) mailto:suchithra@nokia.com>> wrote: Hi, When can we expect the flink 1.12 releases with log4j 2.17.1?

Re: CVE-2021-44228 - Log4j2 vulnerability

2022-01-08 Thread David Morávek
kia.com>; Chesnay Schepler ; User < > user@flink.apache.org>; Michael Guterl ; Richard > Deurwaarder ; Parag Somani > *Subject:* Re: CVE-2021-44228 - Log4j2 vulnerability > > > > Hi all, > > > > The ticket for upgrading Log4J to 2.17.0 is > https://i

RE: CVE-2021-44228 - Log4j2 vulnerability

2022-01-08 Thread V N, Suchithra (Nokia - IN/Bangalore)
Schepler ; User ; Michael Guterl ; Richard Deurwaarder ; Parag Somani Subject: Re: CVE-2021-44228 - Log4j2 vulnerability Hi all, The ticket for upgrading Log4J to 2.17.0 is https://issues.apache.org/jira/browse/FLINK-25375. There's also the update to Log4j 2.17.1 which is tracked under https

Re: CVE-2021-44228 - Log4j2 vulnerability

2022-01-06 Thread Martijn Visser
gt; mart...@ververica.com>, V N, Suchithra (Nokia - IN/Bangalore) < > suchithra....@nokia.com>, Chesnay Schepler , user < > user@flink.apache.org>, Michael Guterl , Richard > Deurwaarder , Parag Somani > *Subject: *Re: CVE-2021-44228 - Log4j2 vulnerability > > Pl

Re: CVE-2021-44228 - Log4j2 vulnerability

2022-01-06 Thread Patrick.Eifler
hard Deurwaarder , Parag Somani Subject: Re: CVE-2021-44228 - Log4j2 vulnerability Please follow the above mentioned ML thread for more details. Please note that this is a REGULAR release that is not motivated by the log4j CVE, so the stability of the release is the more important factor then ha

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-29 Thread David Morávek
; Can you suggest, when can I get binaries for 1.14.2 flink version? >>>>> >>>>> >>>>> >>>>> On Thu, Dec 16, 2021 at 5:52 AM Chesnay Schepler >>>>> wrote: >>>>> >>>>> We will push docker images for

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-26 Thread narasimha
;>> <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105>) >>>> >>>> Refer : https://logging.apache.org/log4j/2.x/security.html >>>> >>>> Any update on this please? >>>> >>>> >>>> >>>&g

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-22 Thread David Morávek
t;>> >>> On Wed, Dec 15, 2021 at 3:26 AM Chesnay Schepler >>> wrote: >>> >>> The current ETA is 40h for an official announcement. >>> >>> We are validating the release today (concludes in 16h), publish it >>> tonight, then wa

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-21 Thread Debraj Manna
gt; >> >> >> *From:* Chesnay Schepler >> *Sent:* Thursday, December 16, 2021 4:35 PM >> *To:* Parag Somani >> *Cc:* Michael Guterl ; V N, Suchithra (Nokia - >> IN/Bangalore) ; Richard Deurwaarder < >> rich...@xeli.eu>; user >> *Subject:* R

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-20 Thread Martijn Visser
, > > Suchithra > > > > *From:* Chesnay Schepler > *Sent:* Thursday, December 16, 2021 4:35 PM > *To:* Parag Somani > *Cc:* Michael Guterl ; V N, Suchithra (Nokia - > IN/Bangalore) ; Richard Deurwaarder < > rich...@xeli.eu>; user > *Subject:* Re: CVE-2021

RE: Suspected SPAM - RE: CVE-2021-44228 - Log4j2 vulnerability

2021-12-18 Thread V N, Suchithra (Nokia - IN/Bangalore)
From: V N, Suchithra (Nokia - IN/Bangalore) Sent: Saturday, December 18, 2021 9:20 PM To: Chesnay Schepler ; user Cc: Michael Guterl ; Richard Deurwaarder ; Parag Somani Subject: Suspected SPAM - RE: CVE-2021-44228 - Log4j2 vulnerability Hi, It seems there is high severity vulnerability

RE: CVE-2021-44228 - Log4j2 vulnerability

2021-12-18 Thread V N, Suchithra (Nokia - IN/Bangalore)
ursday, December 16, 2021 4:35 PM To: Parag Somani Cc: Michael Guterl ; V N, Suchithra (Nokia - IN/Bangalore) ; Richard Deurwaarder ; user Subject: Re: CVE-2021-44228 - Log4j2 vulnerability We will announce the releases when the binaries are available. On 16/12/2021 05:37, Parag Somani wrote: Tha

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-16 Thread Chesnay Schepler
*Cc:* user <mailto:user@flink.apache.org> *Subject:* Re: CVE-2021-44228 - Log4j2 vulnerability We will also update the docker images. On 15/12/2021 11:29, Richard Deurwaarder wrote: Thanks for picking this up quickly! I saw yo

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-15 Thread Parag Somani
waiting for the CVE fix. >> >> >> >> Regards, >> >> Suchithra >> >> >> >> >> >> *From:* Chesnay Schepler >> *Sent:* Wednesday, December 15, 2021 4:04 PM >> *To:* Richard Deurwaarder >> *Cc:* user >> *Su

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-15 Thread Chesnay Schepler
ect:* Re: CVE-2021-44228 - Log4j2 vulnerability We will also update the docker images. On 15/12/2021 11:29, Richard Deurwaarder wrote: Thanks for picking this up quickly! I saw you've made a second minor upgrade to upgrade to log4j2 2.16 which is perfect.

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-15 Thread Michael Guterl
Suchithra > > > > > > *From:* Chesnay Schepler > *Sent:* Wednesday, December 15, 2021 4:04 PM > *To:* Richard Deurwaarder > *Cc:* user > *Subject:* Re: CVE-2021-44228 - Log4j2 vulnerability > > > > We will also update the docker images. > > > > On

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-15 Thread Chesnay Schepler
both versions within ETA mentioned? *From:*Chesnay Schepler *Sent:* Wednesday, December 15, 2021 4:56 PM *To:* V N, Suchithra (Nokia - IN/Bangalore) ; Richard Deurwaarder ; user *Subject:* Re: CVE-2021-44228 - Log4j2 vulnerability The current ETA is 40h for an official announcement. We

RE: CVE-2021-44228 - Log4j2 vulnerability

2021-12-15 Thread V N, Suchithra (Nokia - IN/Bangalore)
of 1.12.6 only or we can expect both versions within ETA mentioned? From: Chesnay Schepler Sent: Wednesday, December 15, 2021 4:56 PM To: V N, Suchithra (Nokia - IN/Bangalore) ; Richard Deurwaarder ; user Subject: Re: CVE-2021-44228 - Log4j2 vulnerability The current ETA is 40h for an official

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-15 Thread Chesnay Schepler
tell when we can expect Flink 1.12.7 release? We are waiting for the CVE fix. Regards, Suchithra *From:*Chesnay Schepler *Sent:* Wednesday, December 15, 2021 4:04 PM *To:* Richard Deurwaarder *Cc:* user *Subject:* Re: CVE-2021-44228 - Log4j2 vulnerability We will also update the docker images

RE: CVE-2021-44228 - Log4j2 vulnerability

2021-12-15 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, Could you please tell when we can expect Flink 1.12.7 release? We are waiting for the CVE fix. Regards, Suchithra From: Chesnay Schepler Sent: Wednesday, December 15, 2021 4:04 PM To: Richard Deurwaarder Cc: user Subject: Re: CVE-2021-44228 - Log4j2 vulnerability We will also

RE: CVE-2021-44228 - Log4j2 vulnerability

2021-12-15 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, Could you please tell when we can expect Flink 1.12.7 release? We are waiting for the CVE fix. Regards, Suchithra From: Chesnay Schepler Sent: Wednesday, December 15, 2021 4:04 PM To: Richard Deurwaarder Cc: user Subject: Re: CVE-2021-44228 - Log4j2 vulnerability We will also update

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-15 Thread Chesnay Schepler
We will also update the docker images. On 15/12/2021 11:29, Richard Deurwaarder wrote: Thanks for picking this up quickly! I saw you've made a second minor upgrade to upgrade to log4j2 2.16 which is perfect. Just to clarify: Will you also push new docker images for these releases as well?

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-15 Thread Richard Deurwaarder
Thanks for picking this up quickly! I saw you've made a second minor upgrade to upgrade to log4j2 2.16 which is perfect. Just to clarify: Will you also push new docker images for these releases as well? In particular flink 1.11.6 (Sorry we must upgrade soon! :() On Tue, Dec 14, 2021 at 2:33 AM

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-13 Thread narasimha
Thanks TImo, that was helpful. On Mon, Dec 13, 2021 at 7:19 PM Prasanna kumar < prasannakumarram...@gmail.com> wrote: > Chesnay Thank you for the clarification. > > On Mon, Dec 13, 2021 at 6:55 PM Chesnay Schepler > wrote: > >> The flink-shaded-zookeeper jars do not contain log4j. >> >> On

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-13 Thread Prasanna kumar
Chesnay Thank you for the clarification. On Mon, Dec 13, 2021 at 6:55 PM Chesnay Schepler wrote: > The flink-shaded-zookeeper jars do not contain log4j. > > On 13/12/2021 14:11, Prasanna kumar wrote: > > Does Zookeeper have this vulnerability dependency ? I see references to > log4j in Shaded

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-13 Thread Chesnay Schepler
The flink-shaded-zookeeper jars do not contain log4j. On 13/12/2021 14:11, Prasanna kumar wrote: Does Zookeeper have this vulnerability dependency ? I see references to log4j in Shaded Zookeeper jar included as part of the flink distribution. On Mon, Dec 13, 2021 at 1:40 PM Timo Walther

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-13 Thread Prasanna kumar
Does Zookeeper have this vulnerability dependency ? I see references to log4j in Shaded Zookeeper jar included as part of the flink distribution. On Mon, Dec 13, 2021 at 1:40 PM Timo Walther wrote: > While we are working to upgrade the affected dependencies of all > components, we recommend

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-13 Thread Timo Walther
While we are working to upgrade the affected dependencies of all components, we recommend users follow the advisory of the Apache Log4j Community. Also Ververica platform can be patched with a similar approach: To configure the JVMs used by Ververica Platform, you can pass custom Java options

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-10 Thread narasimha
Folks, what about the veverica platform. Is there any mitigation around it? On Fri, Dec 10, 2021 at 3:32 PM Chesnay Schepler wrote: > I would recommend to modify your log4j configurations to set > log4j2.formatMsgNoLookups to true*.* > > As far as I can tell this is equivalent to upgrading

Re: CVE-2021-44228 - Log4j2 vulnerability

2021-12-10 Thread Chesnay Schepler
I would recommend to modify your log4j configurations to set log4j2.formatMsgNoLookups to true/./ / / As far as I can tell this is equivalent to upgrading log4j, which just disabled this lookup by default. / / On 10/12/2021 10:21, Richard Deurwaarder wrote: Hello, There has been a log4j2

CVE-2021-44228 - Log4j2 vulnerability

2021-12-10 Thread Richard Deurwaarder
Hello, There has been a log4j2 vulnerability made public https://www.randori.com/blog/cve-2021-44228/ which is making some waves :) This post even explicitly mentions Apache Flink: https://securityonline.info/apache-log4j2-remote-code-execution-vulnerability-alert/ And fortunately, I saw this