[ https://issues.apache.org/jira/browse/PHOENIX-5978?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Istvan Toth resolved PHOENIX-5978. ---------------------------------- Assignee: Istvan Toth Resolution: Fixed Phoenix no longer uses log4j1 on either branch. > Log4j CVE in Phoenix client jar > ------------------------------- > > Key: PHOENIX-5978 > URL: https://issues.apache.org/jira/browse/PHOENIX-5978 > Project: Phoenix > Issue Type: Bug > Affects Versions: 4.14.1 > Reporter: Abhishek > Assignee: Istvan Toth > Priority: Major > Fix For: 5.2.0, 5.1.3 > > > Log4j CVE's being reported on the client jar as it uses log4j 1.2 version. > CVE's being reported are CVE-2020-9488 which is fixed in log4j 2.x version. -- This message was sent by Atlassian Jira (v8.20.10#820010)