Brahma Reddy Battula created HADOOP-17221: ---------------------------------------------
Summary: Upgrade log4j-1.2.17 to atlassian ( To Adress: CVE-2019-17571) Key: HADOOP-17221 URL: https://issues.apache.org/jira/browse/HADOOP-17221 Project: Hadoop Common Issue Type: Bug Reporter: Brahma Reddy Battula Currentlly there are no active release under 1.X in log4j and log4j2 is incompatiable to upgrade (see HADOOP-16206 ) for more details. But following CVE is reported on log4j 1.2.17..I think,we should consider to update to Atlassian([https://mvnrepository.com/artifact/log4j/log4j/1.2.17-atlassian-0.4]) or redhat versions [https://nvd.nist.gov/vuln/detail/CVE-2019-17571] -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: common-dev-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-dev-h...@hadoop.apache.org