Hi, as per page below, log4j CVE is already fixed in ignite 2.11.1
https://blogs.apache.org/ignite/entry/apache-ignite-2-11-1

Affected log4j versions were 2.0-2.14. I can see ignite 2.11.1 contains two
log4j jar files below. Can you please confirm these log4j versions are not
affected by CVE anymore ? Or did I miss something?

ignite-log4j-2.11.1.jar
log4j-1.2.17.jar

Reply via email to