[ 
https://issues.apache.org/jira/browse/LUCENE-10303?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17458965#comment-17458965
 ] 

Tomoko Uchida edited comment on LUCENE-10303 at 12/14/21, 8:06 AM:
-------------------------------------------------------------------

It seems the concerns and worries on this CVE grow bigger and bigger.
I think we don't need a security update/patch release (9.0.1) for this since 
there is no substantial concern in terms of the Luke app (and just replacing 
the log4j jars ("api" and "core") with the latest ones is a perfectly fine 
solution if there is anyone who needs it). ?
Though... Please let me know if it's required.


was (Author: tomoko uchida):
It seems the concerns and worries on this CVE grow bigger and bigger.
I think we don't need a security update/patch for this since there is no 
substantial concern in terms of the Luke app (and just replacing the log4j jars 
("api" and "core") with the latest ones is a perfectly fine solution if there 
is anyone who needs it). ?
Though... Please let me know if it's required.

> Upgrade log4j to 2.15.0
> -----------------------
>
>                 Key: LUCENE-10303
>                 URL: https://issues.apache.org/jira/browse/LUCENE-10303
>             Project: Lucene - Core
>          Issue Type: Task
>            Reporter: Tomoko Uchida
>            Assignee: Tomoko Uchida
>            Priority: Minor
>             Fix For: 9.1, 10.0 (main)
>
>         Attachments: LUCENE-10303.patch
>
>
> CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker 
> controlled LDAP and other JNDI related endpoints.
> Versions Affected: all versions from 2.0-beta9 to 2.14.1
> [https://logging.apache.org/log4j/2.x/security.html]
>  
> Only luke module uses log4j 2.13.2 (I grepped the entire codebase); meanwhile 
> the versions.props is shared by all subprojects, it may be better to upgrade 
> to 2.15.0 I think.



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to