4 ms·
Do anyone know if I depends on the following 2: - org.apache.logging.log4j:log4j-api - org.apache.logging.log4j:log4j-to-slf4j But without dependency on
by pqyzwbq 5y ago
Do anyone know if I depends on the following 2:
- org.apache.logging.log4j:log4j-api
- org.apache.logging.log4j:log4j-to-slf4j
But without dependency on
- org.apache.logging.log4j:log4j-core
in this situation, is this safe from this RCE? Thanks.
Edit, This may affect both log4j 2.x
and log4j 1.x (see comments bellow, thanks.)
- agwa 5y ago> By the way. This only affect log4j 2.x (https://github.com/apache/logging-log4j2 https://github.com/apache/logging-log4j2). the log4j 1.x (https://github.com/apache/log4j https://github.com/apache/log4j) is not affected. That's not what https://github.com/apache/logging-log4j2/pull/608#issuecomment-990494126 https://github.com/apache/logging-log4j2/pull/608#issuecomme... says
- pqyzwbq 5y agoOK, thanks, didn't notice this when I read it.
- deleted 5y ago[deleted]
- pqyzwbq 5y agoNoticed this is answered in: https://github.com/apache/logging-log4j2/pull/608#issuecomment-990661374 https://github.com/apache/logging-log4j2/pull/608#issuecomme... ``` I believe that applications that use log4j-api with log4j-to-slf4j, without using log4j-core, are not impacted by this vulnerability. (Because the lookup and JNDI implementations are in log4j-core.) ```