multiLJT opened a new issue, #12703:
URL: https://github.com/apache/dolphinscheduler/issues/12703

   ### Search before asking
   
   - [X] I had searched in the 
[issues](https://github.com/apache/dolphinscheduler/issues?q=is%3Aissue) and 
found no similar issues.
   
   
   ### What happened
   
   in 2.0.6,CVE-2022-26884 I checked commit for this vulnerability. It seems 
that the code modified by this vulnerability limits the log directory to only 
the logs directory under the installation directory. If the log.base value of 
logback-worker.xml is modified, it cannot match
   
   ### What you expected to happen
   
   Modifying the log.base value of logback-worker.xml will not affect 
LoggerRequestProcessor.java of loggeserver
   
   ### How to reproduce
   
   
   Modify the log.base value of logback-worker.xml
   
   ### Anything else
   
   _No response_
   
   ### Version
   
   2.0.x
   
   ### Are you willing to submit PR?
   
   - [X] Yes I am willing to submit a PR!
   
   ### Code of Conduct
   
   - [X] I agree to follow this project's [Code of 
Conduct](https://www.apache.org/foundation/policies/conduct)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: 
[email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to