Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

iot-device-java引用了log4j,帮忙升级下咯 #11

Open
zhuCheer opened this issue Dec 16, 2021 · 5 comments
Open

iot-device-java引用了log4j,帮忙升级下咯 #11

zhuCheer opened this issue Dec 16, 2021 · 5 comments

Comments

@zhuCheer
Copy link

iot-device-java引用了log4j,帮忙升级下咯

@larrytin
Copy link
Contributor

在处理中

@sevenhhe
Copy link
Contributor

@zhuCheer 你们需要升级 log4j 的原因是什么呢?因为 log4j 的漏洞,还是接口不匹配?

@oulaly
Copy link

oulaly commented Apr 25, 2022

log4j 有 CVE 漏洞,com.tencent.iot.hub.device.java.utils.Loggor 直接用的 log4j,可以改为同时适配 logback 和 log4j 吗

@SundoggyNew
Copy link
Collaborator

已升级log4j版本,可使用3.3.10版本。

@oulaly
Copy link

oulaly commented May 24, 2022

image
没有指定 type 为 pom,下载依赖时会提示找不到 jar

https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j/2.17.2
image

而且还是存在有漏洞的 log4j 1.2.17 版本依赖
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants