[
https://issues.apache.org/jira/browse/HADOOP-18050?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Wei-Chiu Chuang resolved HADOOP-18050.
--------------------------------------
Resolution: Done
> Document Hadoop's stance on the log4jshell vulnerability
> --------------------------------------------------------
>
> Key: HADOOP-18050
> URL: https://issues.apache.org/jira/browse/HADOOP-18050
> Project: Hadoop Common
> Issue Type: Task
> Components: documentation
> Reporter: Wei-Chiu Chuang
> Assignee: Wei-Chiu Chuang
> Priority: Blocker
> Labels: pull-request-available
> Time Spent: 2h 50m
> Remaining Estimate: 0h
>
> As of today, Hadoop relies on log4j-1, not log4j2. It is understood that the
> log4jshell vulnerability (CVE-2021-44228) does not impact log4j-1. Given the
> widespread attention to the incidence, we should make it clear that Hadoop is
> not susceptible to the attack.
--
This message was sent by Atlassian Jira
(v8.20.1#820001)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]