[
https://issues.apache.org/jira/browse/LUCENE-10303?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17459015#comment-17459015
]
Uwe Schindler edited comment on LUCENE-10303 at 12/14/21, 9:43 AM:
-------------------------------------------------------------------
No patch release needed for Lucene 9.0, as there's no remote access to Luke. I
am not sure about Lucene replicator, is it used there, too?
was (Author: thetaphi):
No patch release needed for Lucene 9.0, as there's no idde for Luke. I am not
sure about Lucene replicator, is it used there, too?
> Upgrade log4j to 2.15.0
> -----------------------
>
> Key: LUCENE-10303
> URL: https://issues.apache.org/jira/browse/LUCENE-10303
> Project: Lucene - Core
> Issue Type: Task
> Reporter: Tomoko Uchida
> Assignee: Tomoko Uchida
> Priority: Minor
> Fix For: 9.1, 10.0 (main)
>
> Attachments: LUCENE-10303.patch
>
>
> CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker
> controlled LDAP and other JNDI related endpoints.
> Versions Affected: all versions from 2.0-beta9 to 2.14.1
> [https://logging.apache.org/log4j/2.x/security.html]
>
> Only luke module uses log4j 2.13.2 (I grepped the entire codebase); meanwhile
> the versions.props is shared by all subprojects, it may be better to upgrade
> to 2.15.0 I think.
--
This message was sent by Atlassian Jira
(v8.20.1#820001)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]