https://bugs.kde.org/show_bug.cgi?id=450294
Bug ID: 450294 Summary: Vurnability to CVE-2021-44228 in Apache Log4j framework Product: kdenlive Version: 21.04.3 Platform: Microsoft Windows OS: Microsoft Windows Status: REPORTED Severity: normal Priority: NOR Component: Installation Assignee: vpi...@kde.org Reporter: danny.zwa...@kronoberg.se CC: vpi...@kde.org Depends on: 449822 Target Milestone: --- +++ This bug was initially created as a clone of Bug #449822 +++ SUMMARY Our IT dept was not fully satisfied with the answer given on Bug#449822 . According to them there is a risk that Java is used embedded in other programming languages and therefore a possiblilty that Log4j is used somewhere embedded in the programming language used for Kdenlive. They would like to get a statement that "Kdenlive version 21.04.3 is NOT affected by vurnerabilities in Log4j (CVE-2021-44228)". Can you confirm this statement? SOFTWARE/OS VERSIONS Windows: 10 (Version 10.0.18363.2037) Referenced Bugs: https://bugs.kde.org/show_bug.cgi?id=449822 [Bug 449822] Vurnability to CVE-2021-44228 in Apache Log4j framework -- You are receiving this mail because: You are watching all bug changes.