Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

log4j 漏洞, Nacos没有风险 #226

Closed
abadfox233 opened this issue Dec 10, 2021 · 5 comments
Closed

log4j 漏洞, Nacos没有风险 #226

abadfox233 opened this issue Dec 10, 2021 · 5 comments

Comments

@abadfox233
Copy link

如题

@paderlol
Copy link
Collaborator

Nacos没有使用log4j做日志框架,server一直使用的logback,另外客户端的日志框架是optional选项,所以不太明白你说的升级指什么??

@abadfox233
Copy link
Author

好吧~_~,我以为nacos会有影响

@yanlinly yanlinly changed the title log4j 漏洞, 大概什么时候会发布新的镜像 log4j 漏洞, Nacos没有风险 Dec 11, 2021
@yanlinly yanlinly pinned this issue Dec 11, 2021
@pccai
Copy link

pccai commented Dec 16, 2021

但是nacos包里面有这个文件:
image

@pccai
Copy link

pccai commented Dec 16, 2021

低于2.15.0.RC2,所以能从nacos-server.jar包里面移除吗?

@paderlol
Copy link
Collaborator

低于2.15.0.RC2,所以能从nacos-server.jar包里面移除吗?

出问题需要log4j-core这个包才是bug包
image

原文出处 https://spring.io/blog/2021/12/10/log4j2-vulnerability-and-spring-boot

Nacos目前也会去升级,但是这个并不会造成 0 day

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants