alibaba / alibaba/DataX

CVE-2021-4104: log4j-1.2.17.jar vulnerability

Open
#2,276 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
17.4k
Forks
5.7k
PR merge metrics
No merged PRs in 30d

Description

Hi Team,

we have met the log4j-1.2.17.jar vulnerability, can i replace directly it using log4j-2.x?

Thanks

Contributor guide

No contributing guide indexed for this repository

Research direction

No source files, tests, or entry points are named. Start by locating where DataX uses log4j-1.2.17.jar and check whether replacing it with log4j-2.x is compatible; done means addressing the reported CVE without breaking the affected integration.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.