<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Which log4j version in ACS Community 6.1.2ga (201901)? in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/which-log4j-version-in-acs-community-6-1-2ga-201901/m-p/144414#M38328</link>
    <description>&lt;P&gt;&lt;SPAN&gt;As you indicate that Alfresco makes use of the log4j version 1.2.17 library, I have seen that it also has a vulnerability: &lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2019-17571" target="_blank" rel="nofollow noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2019-17571&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Should any corrective be applied to Alfresco based on this?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Dec 2021 10:20:13 GMT</pubDate>
    <dc:creator>loisVillar</dc:creator>
    <dc:date>2021-12-20T10:20:13Z</dc:date>
    <item>
      <title>Which log4j version in ACS Community 6.1.2ga (201901)?</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/which-log4j-version-in-acs-community-6-1-2ga-201901/m-p/144412#M38326</link>
      <description>&lt;P&gt;Hi, can you help me to find witch version of log4j is used in alfresco-content-services-community-distribution-6.1.2-ga (201901).&lt;/P&gt;&lt;P&gt;I found only this information:&lt;/P&gt;&lt;PRE&gt;&amp;lt;plugin&amp;gt;
  &amp;lt;artifactId&amp;gt;maven-dependency-plugin&amp;lt;/artifactId&amp;gt;
  &amp;lt;executions&amp;gt;
    &amp;lt;!-- CLOUD-1967 Put core log4j config in WEB-INF/classes, so that it's first in classloader --&amp;gt;
    &amp;lt;execution&amp;gt;
      &amp;lt;id&amp;gt;fetch-log4j-config&amp;lt;/id&amp;gt;
      &amp;lt;phase&amp;gt;prepare-package&amp;lt;/phase&amp;gt;
      &amp;lt;goals&amp;gt;
        &amp;lt;goal&amp;gt;unpack&amp;lt;/goal&amp;gt;
      &amp;lt;/goals&amp;gt;
      &amp;lt;configuration&amp;gt;
        &amp;lt;artifactItems&amp;gt;
          &amp;lt;artifactItem&amp;gt;
            &amp;lt;groupId&amp;gt;org.alfresco&amp;lt;/groupId&amp;gt;
            &amp;lt;artifactId&amp;gt;alfresco-core&amp;lt;/artifactId&amp;gt;
          &amp;lt;/artifactItem&amp;gt;
        &amp;lt;/artifactItems&amp;gt;
        &amp;lt;includes&amp;gt;log*.properties&amp;lt;/includes&amp;gt;
        &amp;lt;outputDirectory&amp;gt;${project.build.outputDirectory}&amp;lt;/outputDirectory&amp;gt;
      &amp;lt;/configuration&amp;gt;
    &amp;lt;/execution&amp;gt;
  &amp;lt;/executions&amp;gt;
&amp;lt;/plugin&amp;gt;&lt;/PRE&gt;&lt;P&gt;Where is used version of log4j?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 10:46:50 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/which-log4j-version-in-acs-community-6-1-2ga-201901/m-p/144412#M38326</guid>
      <dc:creator>gsardisco</dc:creator>
      <dc:date>2021-12-13T10:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: Which log4j version in ACS Community 6.1.2ga (201901)?</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/which-log4j-version-in-acs-community-6-1-2ga-201901/m-p/144413#M38327</link>
      <description>&lt;P&gt;log4j-1.2.17.jar&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 11:03:04 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/which-log4j-version-in-acs-community-6-1-2ga-201901/m-p/144413#M38327</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2021-12-13T11:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: Which log4j version in ACS Community 6.1.2ga (201901)?</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/which-log4j-version-in-acs-community-6-1-2ga-201901/m-p/144414#M38328</link>
      <description>&lt;P&gt;&lt;SPAN&gt;As you indicate that Alfresco makes use of the log4j version 1.2.17 library, I have seen that it also has a vulnerability: &lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2019-17571" target="_blank" rel="nofollow noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2019-17571&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Should any corrective be applied to Alfresco based on this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 10:20:13 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/which-log4j-version-in-acs-community-6-1-2ga-201901/m-p/144414#M38328</guid>
      <dc:creator>loisVillar</dc:creator>
      <dc:date>2021-12-20T10:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: Which log4j version in ACS Community 6.1.2ga (201901)?</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/which-log4j-version-in-acs-community-6-1-2ga-201901/m-p/144415#M38329</link>
      <description>&lt;P&gt;If you are using SocketApppender (not provided by default in Alfresco configuration), then you need to upgrade the Log4j library.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 14:39:29 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/which-log4j-version-in-acs-community-6-1-2ga-201901/m-p/144415#M38329</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2021-12-20T14:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Which log4j version in ACS Community 6.1.2ga (201901)?</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/which-log4j-version-in-acs-community-6-1-2ga-201901/m-p/144416#M38330</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The attack is weaker compared to Log4j version 2.x. To verify if you are using this appender, double check your log4j configuration files for presence of org.apache.log4j.net.JMSAppender class.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 15:30:40 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/which-log4j-version-in-acs-community-6-1-2ga-201901/m-p/144416#M38330</guid>
      <dc:creator>Kohler</dc:creator>
      <dc:date>2021-12-27T15:30:40Z</dc:date>
    </item>
  </channel>
</rss>

