Article 5T1NV Apache log4j CVE

Apache log4j CVE

by
Linux_Kidd
from LinuxQuestions.org on (#5T1NV)
Anyone can answer this?

Was the fix for log4j(2) changed in the v15 API or CORE jar file?

I ask because one thought of remediation is to surgically swap out just one jar file on the system to remediate the attack vector.

log4j is a package of various jar files, but now wondering where Apache did the actual fixing.

Or did they fix anything at all? Did they just supply a new package that has modified default properties?latest?d=yIl2AUoC8zA latest?i=Hny1-1BYiEQ:xoFY8H7fu68:F7zBnMy latest?i=Hny1-1BYiEQ:xoFY8H7fu68:V_sGLiP latest?d=qj6IDK7rITs latest?i=Hny1-1BYiEQ:xoFY8H7fu68:gIN9vFw
External Content
Source RSS or Atom Feed
Feed Location https://feeds.feedburner.com/linuxquestions/latest
Feed Title LinuxQuestions.org
Feed Link https://www.linuxquestions.org/questions/
Reply 0 comments