OpenAPITools / OpenAPITools/openapi-generator
[BUG] Verifying that cve-2021-44228 (Apache Log4J / Log4Shell) does not affect openapi-generator
Open
Nobody has claimed this yet.
Issue: Bug
- Dominant language
- Java
- Stars
- 26.8k
- Forks
- 7.7k
- PR merge metrics
- PR metrics pending
Description
Description
This is a general request for a statement. I am not a java dev but looking through the code dependencies, this project relies on slf4j for logging and not Log4J 2. Am I reading everything correctly?
openapi-generator version
Current Master version 5.3.0
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No file or test is named in the issue. Start by reviewing the project's dependency declarations on the current master branch, trace logging dependencies for any Log4J 2 usage, and document a clear conclusion about whether CVE-2021-44228 affects the project.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100