[
https://issues.apache.org/jira/browse/KARAF-7299?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Jean-Baptiste Onofré resolved KARAF-7299.
-----------------------------------------
Target Version/s: (was: 4.4.0, 4.3.5, 4.2.14)
Resolution: Duplicate
> Review logback CVE-2021-42550 for impact to karaf
> --------------------------------------------------
>
> Key: KARAF-7299
> URL: https://issues.apache.org/jira/browse/KARAF-7299
> Project: Karaf
> Issue Type: Task
> Components: karaf
> Affects Versions: 4.2.12, 4.3.3
> Reporter: Matt Pavlovich
> Assignee: Jean-Baptiste Onofré
> Priority: Major
>
> Logback CVE-2021-42550 along the lines of Log4Shell.
> logback fixed in v1.2.9
> Notes:
> # Karaf does not install logback bundle from pax-logging by default
> # there is no feature to install pax-logging-logback
> # Users must manually enable logback
> ref: https://jira.qos.ch/browse/LOGBACK-1591
--
This message was sent by Atlassian Jira
(v8.20.1#820001)