Brahma Reddy Battula created HADOOP-17221:
---------------------------------------------
Summary: Upgrade log4j-1.2.17 to atlassian ( To Adress:
CVE-2019-17571)
Key: HADOOP-17221
URL: https://issues.apache.org/jira/browse/HADOOP-17221
Project: Hadoop Common
Issue Type: Bug
Reporter: Brahma Reddy Battula
Currentlly there are no active release under 1.X in log4j and log4j2 is
incompatiable to upgrade (see HADOOP-16206 ) for more details.
But following CVE is reported on log4j 1.2.17..I think,we should consider to
update to
Atlassian([https://mvnrepository.com/artifact/log4j/log4j/1.2.17-atlassian-0.4])
or redhat versions
[https://nvd.nist.gov/vuln/detail/CVE-2019-17571]
--
This message was sent by Atlassian Jira
(v8.3.4#803005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]