2 ms·
Does that mean it's only vulnerable if JMSAppender is used otherwise not? Which should at least be a rarer use case.
by tmd83 5y ago
Does that mean it's only vulnerable if JMSAppender is used otherwise not? Which should at least be a rarer use case.
- philipwhiuk 5y agoLog4J 1 is only vulnerable for JMS Log4J 2 is vulnerable < 2.15.0. There are mitigations for > 2.10.0 and > 2.7.0