Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bugfix: 修复log4j1.x配置代码执行漏洞(CVE-2021-4104) #1756

Closed
liuliaozhong opened this issue Feb 21, 2023 · 0 comments
Closed

bugfix: 修复log4j1.x配置代码执行漏洞(CVE-2021-4104) #1756

liuliaozhong opened this issue Feb 21, 2023 · 0 comments
Assignees
Labels
done 已上线到正式环境并验收通过 kind/bug 程序故障Bug,漏洞 stage/prod Production environment in tencent has been deploy

Comments

@liuliaozhong
Copy link
Collaborator

liuliaozhong commented Feb 21, 2023

出了什么问题?(What Happened?)
log4j1.x配置代码执行漏洞(CVE-2021-4104)

如何复现?(How to reproduce?)
job-execute.jar包存在类库log4j-1.2.17.jar。
job使用logback组件管理日志,log4j是curator-framework:5.1.0依赖进来的,但是直接删除会报错。可以升级到最新版,最新版没使用log4j

预期结果(What you expect?)

jar不含log4j-1.2.17.jar

@liuliaozhong liuliaozhong added the kind/bug 程序故障Bug,漏洞 label Feb 21, 2023
@liuliaozhong liuliaozhong self-assigned this Feb 21, 2023
jsonwan added a commit that referenced this issue Feb 22, 2023
bugfix: 修复log4j1.x配置代码执行漏洞(CVE-2021-4104) #1756
jsonwan added a commit that referenced this issue Feb 23, 2023
bugfix: 修复log4j1.x配置代码执行漏洞(CVE-2021-4104) #1756
jsonwan added a commit that referenced this issue Feb 28, 2023
bugfix: 修复log4j1.x配置代码执行漏洞(CVE-2021-4104) #1756
jsonwan added a commit that referenced this issue Mar 3, 2023
bugfix: 修复log4j1.x配置代码执行漏洞(CVE-2021-4104) #1756
@bkjob-bot bkjob-bot added the stage/prod Production environment in tencent has been deploy label Mar 14, 2023
@bkjob-bot bkjob-bot added the done 已上线到正式环境并验收通过 label May 22, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
done 已上线到正式环境并验收通过 kind/bug 程序故障Bug,漏洞 stage/prod Production environment in tencent has been deploy
Projects
None yet
Development

No branches or pull requests

2 participants