https://bz.apache.org/bugzilla/show_bug.cgi?id=65748

--- Comment #9 from Josiah Johnston <[email protected]> ---
+1 to Arjan

I greatly appreciate the Christmas Eve security release (upgrade to 2.17.0),
but looks like Krampus delivered another vulnerability with CVE-2021-44832.
That security patch was delivered a few days after Christmas. AFAIK, the only
robust fix is upgrading to 2.17.1.
https://logging.apache.org/log4j/2.x/security.html

FWIW, I noticed the issue when the CloudStrike CAST tool flagged this file as
vulnerable: /usr/local/Cellar/jmeter/5.4.3/libexec/lib/log4j-core-2.17.0.jar

-- 
You are receiving this mail because:
You are the assignee for the bug.

Reply via email to