Re: Log4j, CVE-2021-44228, and Mahout

2021-12-13 Thread Andrew Musselman
Thanks Trevor; may be a good time to revive our online meetings to talk through this one.. I could find time during the holiday break pretty much any day; if anyone else is interested let us know if there's a good time to chat. On Mon, Dec 13, 2021 at 4:26 PM Trevor Grant wrote: > Many of you h

Log4j, CVE-2021-44228, and Mahout

2021-12-13 Thread Trevor Grant
Many of you have probably become aware of Log4j's vulnerability to CVE-2021-44228 recently. Though Mahout is a sleepy project, we are vigilant and want you to know we are aware of the issue and have been monitoring. First, let me assure you that since Mahout (like over 90% of log4j users) is on v