4 ms·
Noticed this is answered in: https://github.com/apache/logging-log4j2/pull/608#issuecomment-990661374 https://github.com/apache/logging-log4j2/pull/608#issueco
by pqyzwbq 5y ago
Noticed this is answered in: https://github.com/apache/logging-log4j2/pull/608#issuecomment-990661374 https://github.com/apache/logging-log4j2/pull/608#issuecomme...
```
I believe that applications that use log4j-api with log4j-to-slf4j, without using log4j-core, are not impacted by this vulnerability. (Because the lookup and JNDI implementations are in log4j-core.)
```