Romain, Romain>for now the thread is looking for options which are not needed from my window
It was the Logging PMC team who suggested I should re-incubate log4j 1.x. Romain>1. where is the patch needed to fix the desired CVE? - must be compatible with current SVN trunk The current SVN trunk is NOT buildable. It uses outdated build tools, so build system healing is needed before ANY other patches. Romain>2. please attach it to a ticket I have just created https://issues.apache.org/jira/browse/LOG4J2-3272 "Enable Git and GitHub for log4j 1.2 repository" Every patch to 1.x must be well-tested, so attaching patch files to JIRA is a recipe for disaster. I already asked Logging PMC to enable Git and GitHub for 1.x, and they rejected it: https://lists.apache.org/thread/ssbdg44gy7txzl16xxd097t7orco52g2 I do not see why filing the same thing as JIRA would work any better than sending mail to dev@logging list. Vladimir