Re: Impact of CVE-2021-4104

2021-12-18 Thread Aishwarya Soni
Hi, Please go through this https://issues.apache.org/jira/plugins/servlet/mobile#issue/ZOOKEEPER-4423 for the on-going discussion. Regards, Aishwarya Soni On Sat, Dec 18, 2021, 2:00 PM Rusty Deaton wrote: > Hi there, > > Given that zookeeper uses log4j 1.2, it appears as though there's a > pot

Impact of CVE-2021-4104

2021-12-18 Thread Rusty Deaton
Hi there, Given that zookeeper uses log4j 1.2, it appears as though there's a potentially large CVE, https://nvd.nist.gov/vuln/detail/CVE-2021-4104 . Is there any official stance on this vulnerability?

Re: Impact of Log4J security vulnerability CVE-2021-44228 on zookeeper

2021-12-18 Thread Patrick Hunt
Hi Brent, there is a discussion going on on the dev list with subject "Logback" if folks would like to participate. Regards, Patrick On Fri, Dec 17, 2021 at 11:26 PM Brent wrote: > I just finished reading through the latest Jira comments and links. Has > there been any consensus reached thus