[ https://issues.apache.org/jira/browse/KAFKA-13594?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17476142#comment-17476142 ]
Waseem commented on KAFKA-13594: -------------------------------- In our project we have separate installation of project and we have to add kafka as third party software and under kafka folder have log4j-1.2.17.jar file in which getting JMSAppender.class, which showing vulnerability according to sent link by you. after removing JMSAppender.class from Log4j-1.2.17.jar which is available in Kafka 2.6.0 versionĀ does it impact on separate installed application? could you please suggest us ? > In TNPM Wireline Project, vulnerability found in Log4j-1.2.17.jar under KAFKA > directory > --------------------------------------------------------------------------------------- > > Key: KAFKA-13594 > URL: https://issues.apache.org/jira/browse/KAFKA-13594 > Project: Kafka > Issue Type: Task > Components: log, logging > Affects Versions: 2.6.0 > Reporter: Waseem > Priority: Major > Fix For: 2.6.0 > > > In TNPM wireline project, we used kafka2.6.x which is using Log4j-1.2.17.jar > in which we found this JMSAppender.class. > Is this class is vulnerable for Log4j-1.2.17.jar ? > Could you please suggest any steps or refer to any document ? -- This message was sent by Atlassian Jira (v8.20.1#820001)