siddhi-io / siddhi

Stream Processing and Complex Event Processing Engine

Home Page:http://siddhi.io

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

siddhi rely on LOG4j1.x. Is it affected by vulnerability CVE-2022-23302/23305/23307?

winter-wu opened this issue · comments

siddhi rely on LOG4j1.x. Is it affected by vulnerability CVE-2022-23302/23305/23307?
version:v5.0.0, v5.1.11, v5.1.19

We are currently working on upgrading to log4j latest version.

@AnuGayan does the team have an estimated completion time for the log4j upgrade?