3 ms·
Same, all of our Java projects were using 1.X log4j, and have been for years and years without issue. Ironically, all of this scrutiny on the problems of the 2.
by thrower123 5y ago
Same, all of our Java projects were using 1.X log4j, and have been for years and years without issue. Ironically, all of this scrutiny on the problems of the 2.X releases has forced us to agree to update from those rather dumb, safer builds to the latest releases, so that we'll have to be on the treadmill.
- samus 5y agoLog4j 1.x contains vulnerabilities and errors that were never addressed because it was declared end-of-life in 2015 and the Apache project has stopped supporting it! https://logging.apache.org/log4j/1.2/index.html https://logging.apache.org/log4j/1.2/index.html https://www.cvedetails.com/cve/CVE-2019-17571/ https://www.cvedetails.com/cve/CVE-2019-17571/