fulldecent commented on pull request #630:
URL: https://github.com/apache/logging-log4j2/pull/630#issuecomment-998791311


   The Messages are NOT strings nor are they "messages". 
   
   The specification is wrong and therefore it is vulnerable. Sometimes it is 
shell-code vulnerable but definitely at a minimum it is always 
not-logging-as-expected vulnerable. 
   
   I am still working on this PR and there are hundreds of changes required. 
Please reopen. 
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


Reply via email to