Skip to Content.
Sympa Menu

perfsonar-user - Re: [perfsonar-user] Reccomendation for mitigating log4j vuln

Subject: perfSONAR User Q&A and Other Discussion

List archive

Re: [perfsonar-user] Reccomendation for mitigating log4j vuln


Chronological Thread 
  • From: Mark Feit <>
  • To: Hans Kuhn <>
  • Cc: "" <>
  • Subject: Re: [perfsonar-user] Reccomendation for mitigating log4j vuln
  • Date: Fri, 10 Dec 2021 19:21:20 +0000
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=internet2.edu; dmarc=pass action=none header.from=internet2.edu; dkim=pass header.d=internet2.edu; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Ldf0yZs0oILMobc92L9ug9ciI6hXOz4O7H8JXDPt+Bk=; b=bKAa2w3LRjcoA4ewT4Ex6hRnNUePqJBJejc5vEq2TAQOF8byqkSztPbQwd6QNIW9NSn+e2Y+OVut06ob68CrXe5QicAa8RmpOHPp8I1wnnbUscVCRk03EzHCJ3eAd+IZQuD+RCjw03aNGkvUk+MTvYbOTntQlDgws+IXAnYAsw21YA206us3uKb6gZ9aUzm/1kNqbjlCpATeArm04bgNy6JSp++IdtCI0mtXouwLS7cJrosq1WYfjxucEMEOJlElH+929O11ezmfohthU/uylf10WaG+27UYg2+k46VdQ3NgBWiBP5SO8kPqe9IqpEghsZ2+zxyl5/p78jqkxFzzJQ==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=PBZL82KlGx7ZE0mVFs1MC6WU6JmoOm92Yx52jxmdKGhm7lw9dJm5AystXk1mpmLpB/E3iNSSbm9rF56rwrTPQocCx9kzZ5zRQyrYfrCI6GQox0I4V0PsYO1YVsbnKHk3i17WMwD85YeE6GiaQUls0t7xJFS3eP7ZAYb0nP24Sh3FP77LYCDCp4VvhsGJKKkXsLOabOP0QEKofnE46mWHlhOew4W9arc+7jTGxNoSJjH9/tq9UDVrDPv9v7pGC8NE3isNxxxwQt++rhfls2iYBuk69gYJ+PZzkNU8QliKOxpDZ6asAA9mDdNcQyMzn4ZOvpolB5IlDZoeYYp8bz1gOA==

Hans Kuhn writes:

 

Thanks Mark! Can you reassure me that this doesn't apply to pS even tho it runs log4j 1.x?

"The 1.x series of Log4j is also vulnerable to this issue when using the JMS Appender class."

 

All of our Log4j logging goes to files via the RollingFileAppender.  You can see that in the configuration we ship here:  https://github.com/perfsonar/maddash/blob/master/maddash-server/etc/log4j.properties.

 

--Mark

 




Archive powered by MHonArc 2.6.24.

Top of Page