3 ms·
We just didn't update Log4j since it broke a critical, old, closed source offline program. Vendor has long dropped support for this old program. Cue that up to
by glowingly 4y ago
We just didn't update Log4j since it broke a critical, old, closed source offline program. Vendor has long dropped support for this old program. Cue that up to the usual executive missteps that we get from up high.
Yay, we get to keep on using old Log4j now because one program holds it back.
- cesarb 4y agoIf the "old log4j" is 1.2.x, you can update to reload4j (https://reload4j.qos.ch/ https://reload4j.qos.ch/), which is a fork of the latest log4j 1.2.x by its initial author; you don't have to update to log4j 2.x (which changed the API). And you might not even need to update, since "old log4j" (1.2.x) wasn't affected by that vulnerability in the first place (it has its own old vulnerabilities, but they're all in code which is usually not used by real world deployments).