rollcage icon indicating copy to clipboard operation
rollcage copied to clipboard

Does rollcage expose users to the log4shell exploit?

Open jkndrkn opened this issue 3 years ago • 0 comments

rollcage is currently using org.clojure/tools.logging 0.4.0 which depends on a version of log4j that is vulnerable to the log4shell exploit:

https://logging.apache.org/log4j/2.x/security.html

Does rollcage expose users to the log4shell exploit?

Upgrading to tools.logging 1.2.2 would result in loading the recommended log4j version 2.16.0

jkndrkn avatar Dec 15 '21 19:12 jkndrkn