[ANNOUNCEMENT] Apache Logging log4j 2.0-beta3 release

2012-11-14 Thread Ralph Goers
The Apache Logging team is pleased to announce the Apache log4j 2.0-beta2 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many of the

[ANNOUNCEMENT] Apache Log4j 2.0-beta4 released

2013-02-01 Thread Ralph Goers
The Apache Logging team is pleased to announce the Apache log4j 2.0-beta4 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many of the

[ANNOUNCEMENT] Apache Log4j 2.0-beta5 released

2013-04-25 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.0-beta5 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many of the improvements

[ANNOUNCEMENT] Apache Log4j 2.0-beta6 released

2013-05-12 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.0-beta6 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many of the improvements

[ANNOUNCEMENT] Apache Log4j-2.0-beta7 released

2013-06-08 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.0-beta7 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many of the improvements

[ANNOUNCEMENT] Apache Log4j 2.0-beta8 released

2013-07-14 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.0-beta8 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many of the improvements

[ANNOUNCEMENT] Apache Log4j 2.0-beta9 released

2013-09-21 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.0-beta9 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many of the improvements

Log4j 2.0 released

2014-07-17 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.0 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many of the improvements available

Apache Log4j 2.1 released

2014-10-24 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.1 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many of the improvements available

Apache Log4j 2.2 released

2015-02-26 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.2 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such as

[ANNOUNCEMENT] Log4j 2.3 released

2015-05-15 Thread Ralph Goers
. o LOG4J2-1008: org.apache.logging.log4j.core.config.plugins.util.ResolverUtil.extractPath(URL) incorrectly converts '+' characters to spaces. Thanks to Ralph Goers, Gary Gregory. o LOG4J2-1007: org.apache.logging.log4j.core.util#fileFromUri(URI uri) incorrectly converts '+' characters

[ANNOUNCEMENT] Apache Log4j 2.4.1 released

2015-10-13 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.4.1 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such as

[ANNOUNCEMENT] Log4j 2.4 released

2015-09-25 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.4 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such as

[ANNOUNCEMENT] Log4j 2.5 released

2015-12-10 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.5 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such as

[ANNOUNCEMENT] Apache Log4j 2.7 released

2016-10-07 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.7 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such as

[ANNOUNCEMENT] Apache Log4j 2.8.1 released

2017-03-03 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.8.1 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCE] Apache Log4j 2.9.1 released

2017-09-21 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.9.1 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCE] Apache Log4j 2.9.0 released

2017-09-01 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.9.0 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such as

[ANNOUNCE] Apache Log4j 2.9.0 released

2017-08-31 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.9.0 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCEMENT] Apache Log4j 2.10.0 released

2017-11-23 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.10.0 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and providesmany other modern features such

[ANNOUNCE] Apache Log4j Audit 1.0.0 released

2018-06-22 Thread Ralph Goers
The Apache Log4j team is pleased to announce the Apache Log4j Audit 1.0.0 release! Apache Log4j Audit provides a framework for defining audit events and then logging them using Log4j. The framework focuses on defining the events and providing an easy mechanism for applications to log them,

[ANNOUNCEMENT] Apache Log4j2 2.11.0 released

2018-03-17 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.11.0 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCE] Apache Log4j-Audit 1.0.1 released

2018-12-13 Thread Ralph Goers
The Apache Log4j Audit team is pleased to announce the Log4j Audit 1.0.1 release! Apache Log4j Audit is a framework for performing audit logging using a predefined catalog of audit events. It provides a tool to create and edit audit events. It also provides a REST service to perform the

[ANNOUNCE] Apache Log4j 2.11.2 released

2019-02-09 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.11.2 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCEMENT] Apache Log4j 2.12.0 released

2019-06-30 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.12.0 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCEMENT] Apache Log4j 2.12.1 released!

2019-08-11 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.12.1 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCEMENT] Log4j 2.13.0 released!

2019-12-15 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.13.0 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCMENT] Log4j 2.13.1 released

2020-03-01 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.13.1 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCEMENT] Log4j 2.13.3 Released

2020-05-15 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.13.3 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCEMENT] Apache Log4j 2.14.0 released

2020-11-11 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.14.0 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCEMENT] Log4j 2.14.1 released

2021-03-13 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.14.1 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCE] Apache Log4j 2.12.3 for Java 7 Released

2021-12-21 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.12.3 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCE] Apache Log4j 2.3.1 for Java 6 released

2021-12-21 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.3.1 release! Apache log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such as

[ANNOUNCEMENT] Apache Log4j 2.17.0 Released

2021-12-18 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.17.0 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCE] Apache Log4j 2.12.4 released

2021-12-29 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.12.4 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

2021-12-10 Thread Ralph Goers
Severity: critical Description: Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary

CVE-2021-4104: Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2

2021-12-13 Thread Ralph Goers
Description: JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests

[ANNOUNCEMENT] Apache Log4j 2.15.0 Released

2021-12-10 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.15.0 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCE] Apache Log4j 2.17.2 released

2022-02-28 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.17.2 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

CVE-2022-23305: SQL injection in JDBC Appender in Apache Log4j V1

2022-01-18 Thread Ralph Goers
Severity: high Description: By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the

CVE-2022-23302: Deserialization of untrusted data in JMSSink in Apache Log4j 1.x

2022-01-18 Thread Ralph Goers
Severity: high Description: JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a

CVE-2022-23307: Apache Log4j 1.x: A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.

2022-01-18 Thread Ralph Goers
Severity: Critical Description: CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. Mitigation: Upgrade to Apache Log4j 2 and Apache Chainsaw 2.1.0. Credit:

[ANNOUNCE] Apache Log4j 2.18.0 released

2022-07-03 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.18.0 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCE] Apache Flume 1.10.0 released

2022-06-14 Thread Ralph Goers
The Apache Flume team is pleased to announce the release of Flume version 1.10.0. Flume is a distributed, reliable, and available service for efficiently collecting, aggregating, and moving large amounts of log data. Flume 1.10.0 fixes CVE-2022-25167, a vulnerability in Flume’s JMSSource

CVE-2022-25167 - Apache Flume JMSSource does not protect from malicious JNDI urls

2022-06-14 Thread Ralph Goers
Severity, medium Description: Flume’s JMSSource class can be configured with a connection factory name. A JNDI lookup is performed on this name without performing an validation. This could result in untrusted data being deserialized. Please see https://flume.apache.org/security.html for more

[ANNOUNCE] Apache Flume 1.10.1 released

2022-08-21 Thread Ralph Goers
The Apache Flume team is pleased to announce the release of Flume version 1.10.1. Flume is a distributed, reliable, and available service for efficiently collecting, aggregating, and moving large amounts of log data. Flume 1.10.1 fixes CVE-2022-34916, a vulnerability in Flume’s

CVE-2022-34916: Apache Flume: Improper Input Validation (JNDI Injection) in JMSMessageConsumer

2022-08-21 Thread Ralph Goers
Description: Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the

[ANNOUNCE] Release of Apache Flume 1.11.0

2022-10-25 Thread Ralph Goers
The Apache Flume team is pleased to announce the release of Flume version 1.11.0. Flume is a distributed, reliable, and available service for efficiently collecting, aggregating, and moving large amounts of log data. This release can be downloaded from the Flume download page at:

CVE-2022-42468 - Apache Flume Improper Input Validation (JNDI Injection) in JMSSource

2022-10-25 Thread Ralph Goers
Severity, medium Description: Flume’s JMSSource class can be configured with a providerUrl parameter. A JNDI lookup is performed on this name without performing an validation. This could result in untrusted data being deserialized. Mitigation Upgrade to Flume 1.11.0. In releases 1.4.0

[ANNOUNCE] Apache Log4j 2.19.0 released

2022-09-18 Thread Ralph Goers
The Apache Log4j 2 team is pleased to announce the Log4j 2.19.0 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such

[ANNOUNCE] Apache Log4j 2.20.0 released

2023-02-22 Thread Ralph Goers
P. Karwasz, Federico D’Ambrosio) • Add PatternLayout support for abbreviating the name of all logger components except the 2 rightmost (for LOG4J2-2785 by Ralph Goers, Markus Spann) • Removes internal field that leaked into public API. (for LOG4J2-3615 by Piotr P. Karwasz) • Add a LogBuilder#logAndGe

[ANNCOUNCE] Apache Flume Spring Boot 2.0.0 released

2023-04-04 Thread Ralph Goers
The Apache Flume team is pleased to announce the Flume Spring Boot 2.0.0 release. Flume is a distributed, reliable, and available service for efficiently collecting, aggregating, and moving large amounts of event data. Flume Spring Boot allows Flume, and Flume components, to be packaged and

[ANNOUNCE] Apache Log4j 3.0.0-alpha1 released

2023-06-22 Thread Ralph Goers
ow plugins to be created through more flexible dependency injection patterns. (for LOG4J2-1188 by Matt Sicker) • Allow to force LOG4J2 to use TCCL only. (for LOG4J2-2171 by rmannibucau, Ralph Goers) • Allow web lookup to access more information. (for LOG4J2-2523 by Romain Manni-Bucau, R