Andy Seaborne created JENA-2224: ----------------------------------- Summary: Upgrade to log4j 2.17.0 Key: JENA-2224 URL: https://issues.apache.org/jira/browse/JENA-2224 Project: Apache Jena Issue Type: Task Components: Cmd line tools, Fuseki Affects Versions: Jena 4.3.2 Reporter: Andy Seaborne Assignee: Andy Seaborne Fix For: Jena 4.4.0
https://nvd.nist.gov/vuln/detail/CVE-2021-45105 https://logging.apache.org/log4j/2.x/security.html This only happens if you change the logging pattern. As released Fuseki and command line tools do not use the pattern feature involved in CVE-2021-45105. -- This message was sent by Atlassian Jira (v8.20.1#820001)