[
https://issues.apache.org/jira/browse/PHOENIX-6636?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17498104#comment-17498104
]
Istvan Toth commented on PHOENIX-6636:
--------------------------------------
Committed to all active branches of the Phoenxi repo.
Thanks for the review [~gjacoby] .
Keeping the ticket open, as need to update/review the other repos.
> Replace bundled log4j libraries with reload4j
> ---------------------------------------------
>
> Key: PHOENIX-6636
> URL: https://issues.apache.org/jira/browse/PHOENIX-6636
> Project: Phoenix
> Issue Type: Bug
> Components: connectors, core, queryserver
> Affects Versions: 5.2.0
> Reporter: Istvan Toth
> Assignee: Istvan Toth
> Priority: Major
>
> To reduce the number of dependecies with unresolved CVEs, replace the bundled
> log4j libraries with reload4j ([https://reload4j.qos.ch/).]
> This will also require bumping the slf4j version.
> This is a quick fix, and does not preclude moving to some different backend
> later (like log4j2 or logback)
--
This message was sent by Atlassian Jira
(v8.20.1#820001)