Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable log4j JAR needs updating #82

Open
DavidSewell opened this issue Aug 22, 2022 · 2 comments
Open

Vulnerable log4j JAR needs updating #82

DavidSewell opened this issue Aug 22, 2022 · 2 comments
Assignees
Labels

Comments

@DavidSewell
Copy link

My university is rolling out the requirement to install the Qualys vulnerability checking agent on all systems connected to the network, and the first report on our Manifold host complained about the existence of /opt/manifold/embedded/elasticsearch/lib/log4j-core-2.11.1.jar, referencing this NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2021-44228 .

@zdavis zdavis transferred this issue from ManifoldScholar/manifold Aug 22, 2022
@zdavis
Copy link
Member

zdavis commented Aug 23, 2022

We'll take a look. When this vulnerability came out, we checked our packages and confirmed that Manifold is not vulnerable. However, it does need to be updated, so we'll try to get this fixed in the 7.1 release.

@zdavis zdavis self-assigned this Aug 23, 2022
@zdavis zdavis added the bug label Aug 23, 2022
@DavidSewell
Copy link
Author

DavidSewell commented Aug 23, 2022 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants