Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Nacos是否受到log4j2零日漏洞的影响 #7407

Closed
iigx opened this issue Dec 13, 2021 · 4 comments
Closed

Nacos是否受到log4j2零日漏洞的影响 #7407

iigx opened this issue Dec 13, 2021 · 4 comments
Labels
expired No active for a long time kind/question Category issues related to questions or problems

Comments

@iigx
Copy link

iigx commented Dec 13, 2021

Hello,

咨询一下大家,NACOS的最新版本2.0.3是否受到本次log4j2远程代码执行漏洞的影响?

@li-xiao-shuang
Copy link
Collaborator

可以看下 nacos-group/nacos-docker#226

@li-xiao-shuang li-xiao-shuang added the kind/question Category issues related to questions or problems label Dec 13, 2021
@iigx
Copy link
Author

iigx commented Dec 13, 2021 via email

@wuxiangzhou2010
Copy link

However the docker image have log4j jars, I have one request to remove them

nacos-group/nacos-docker#227

# jar -tvf nacos-server.jar |grep -i log
....
 23702 Mon Dec 16 22:00:18 CST 2019 BOOT-INF/lib/log4j-over-slf4j-1.7.30.jar
 17522 Tue Feb 05 18:14:20 CST 2019 BOOT-INF/lib/log4j-to-slf4j-2.11.2.jar
292301 Sun May 10 12:07:56 CST 2020 BOOT-INF/lib/log4j-api-2.13.3.jar

@stale
Copy link

stale bot commented Jun 19, 2022

Thanks for your feedback and contribution. But the issue/pull request has not had recent activity more than 180 days. This issue/pull request will be closed if no further activity occurs 7 days later.
We may solve this issue in new version. So can you upgrade to newest version and retry?
If there are still issues or want to contribute again. Please create new issue or pull request again.

@stale stale bot added the expired No active for a long time label Jun 19, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
expired No active for a long time kind/question Category issues related to questions or problems
Projects
None yet
Development

No branches or pull requests

4 participants