-
Notifications
You must be signed in to change notification settings - Fork 137
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Affected by CVE-2021-44228? #128
Comments
Kafka is using log4j v1, which is not affected. Only with a specific jmc configuration, it's vulnerable.
Source: https://lists.apache.org/thread/lgbtvvmy68p0059yoyn9qxzosdmx4jdv To be honest, I'm not familiar with this "jms configuration", but hope this info helps. |
Who can identify which kafka images and also confluentinc/cp-kafka-connect images are affected by the vulnerability? |
According to this SO post, Log4J 1.x should only be vulnerable if you have configured the |
Please see Confluent's official stance on this topic: https://support.confluent.io/hc/en-us/articles/4412615410580-December-2021-Log4j-Vulnerabilities-Advisory |
Thanks a lot, this answers it:
With this I will close the issue. Thanks a lot for your input! |
Hi,
can somebody please confirm that the image
confluentinc/cp-kafka:6.0.1
is NOT affected by the log4j vulnerabilityCVE-2021-44228
?If I checked correctly, it uses a custom log4j version based on v1.2.17 (https://github.com/confluentinc/kafka/blob/9c1fbb3db1e0d69d09f165b3b9861fc984ad1a62/gradle/dependencies.gradle#L78), which is not included in the list of affected versions. Still, I want to make sure I am right here.
Thank you!
The text was updated successfully, but these errors were encountered: