Re: Information about Apache Jena and Log4j2 vulnerability.

2021-12-14 Thread Andy Seaborne
On 14/12/2021 12:04, jaa...@kolumbus.fi wrote: Hello, Sorry for asking stupid question, but I'm not sure it would be enough to have just the below setting inside the docker container that runs blankdots/jena-fuseki 3.17 image pulled from docker hub. Disclaimer: blankdots/jena-fuseki isn'

Re: Information about Apache Jena and Log4j2 vulnerability.

2021-12-14 Thread jaanam
Hello, Sorry for asking stupid question, but I'm not sure it would be enough to have just the below setting inside the docker container that runs blankdots/jena-fuseki 3.17 image pulled from docker hub. C:\Users\miettinj>docker exec -it 1a7e /bin/bash root@1a7e400c71aa:/jena-fuseki# echo $J

Re: Information about Apache Jena and Log4j2 vulnerability.

2021-12-12 Thread Andy Seaborne
Please don't mix the focus of the thread. This thread is important information about the Apache Jena project. To be clear to the wider audience: RDF Delta is not under the governance of the Apache Jena PMC. Andy Obviously, the published mitigations work with the combined RDF Delta/Fusek

Re: Information about Apache Jena and Log4j2 vulnerability.

2021-12-10 Thread Brandon Sara
Andy, will you be releasing an RDF-Delta update that uses 4.3.1 soon as well? No PHI in Email: PointClickCare and Collective Medical, A PointClickCare Company, policies prohibit sending protected health information (PHI) by email, which may violate regulatory requirements. If sending PHI is neces

Information about Apache Jena and Log4j2 vulnerability.

2021-12-10 Thread Andy Seaborne
This message is about the effect of CVE-2021-44228 (log4j2) on Fuseki. https://nvd.nist.gov/vuln/detail/CVE-2021-44228 Jena ships log4j2 in Fuseki and the command line tools. The vulnerability of log4j2 does impact Fuseki 3.15 - 3.17, and 4.x. Remote execution is only possible with older versi