G-Node / G-Node/odml-query

Update Apache Fuseki server dependency to permanently remove log4j security vulnerability

Open
#12 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
1
Forks
1
PR merge metrics
No merged PRs in 30d

Description

The log4j version (2.14.1) used in the current build of the Apache Fuseki server contains a severe security vulnerability, see [logging.apache.org](https://logging.apache.org/log4j/2.x/security.html) for details.

Upgrade the Apache Fuseki server as soon as a fixed version (dependency Log4j >= 2.15.0) [is released](https://jena.apache.org/download/) (4.3.0 still contains the vulnerable library). The used version can be checked in `fuseki-server.jar:METAINF/DEPENDENCIES`.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.