[ 
https://issues.apache.org/jira/browse/PHOENIX-6636?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17498354#comment-17498354
 ] 

Lars Hofhansl commented on PHOENIX-6636:
----------------------------------------

(y)

> Replace bundled log4j libraries with reload4j
> ---------------------------------------------
>
>                 Key: PHOENIX-6636
>                 URL: https://issues.apache.org/jira/browse/PHOENIX-6636
>             Project: Phoenix
>          Issue Type: Bug
>          Components: connectors, core, queryserver
>    Affects Versions: 5.2.0
>            Reporter: Istvan Toth
>            Assignee: Istvan Toth
>            Priority: Major
>             Fix For: 4.17.0, 5.2.0, 4.16.2, 5.1.3
>
>
> To reduce the number of dependecies with unresolved CVEs, replace the bundled 
> log4j libraries with reload4j ([https://reload4j.qos.ch/).]
> This will also require bumping the slf4j version.
> This is a quick fix, and does not preclude moving to some different backend 
> later (like log4j2 or logback)



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

Reply via email to