Skip to content

log4j vulnerability via logback-classic? #3785

@kannes

Description

@kannes

Hi you lovely people!

Sorry for abusing the bug tracker for something that is more like a question but I think this is where others might search for "log4j" in the context of OpenTripPlanner.

Is OTP affected by the log4j vulnerability?

From what I found it uses logback-classic and jul-to-slf4j (https://github.com/opentripplanner/OpenTripPlanner/blob/dev-2.x/pom.xml#L390-L400).

logback 1.2.5 as used by OTP seems to be affected: https://jira.qos.ch/browse/LOGBACK-1591

I have no idea what the difference for logback-classic could be and I really have no idea about Java logging at all, so please excuse me if this is a stupid question. I am just a user. Thank you! :)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions