Re: [CentOS] log4j cve

2021-12-15 Thread Ralf Prengel
Zitat von Ralf Prengel : Tools alle Links ohne Prüfung auf Inhalt und Qualität https://log4shell.huntress.com/ (Quelle Sven Kuhnert) https://therecord.media/log4j-zero-day-gets-security-fix-just-as-scans-for-vulnerable-systems-ramp-up/ Sorry, cut & paste error. Ralf ___

Re: [CentOS] log4j cve

2021-12-15 Thread Ralf Prengel
Zitat von Steve Meier : Hello Steve, Am 2021-12-14 14:14, schrieb Steve Clark: This is the standard version that comes with CentOS 7 and is the latest available as of a yum update just now. log4j-1.2.17-16.el7_4.noarch yes, that's correct, but it is abandoned nonetheless. According to the

Re: [CentOS] log4j cve

2021-12-14 Thread Stuart Barkley
On Tue, 14 Dec 2021 at 07:42 -, Steve Clark via CentOS wrote: > I see on CentOS 7 it has log4j-1.2.17... > Is ok 2 use. I know the CVE was against 2.0 fwd but not knowing if something > was backported to 1.2 ? According to https://access.redhat.com/security/vulnerabilities/RHSB-2021-009 Redha

Re: [CentOS] log4j cve

2021-12-14 Thread Markus Falb
On Tue, 2021-12-14 at 14:31 +0100, Steve Meier wrote: > Hello Steve, > > Am 2021-12-14 14:14, schrieb Steve Clark: > > This is the standard version that comes with CentOS 7 and is the > > latest available as of a yum update just now. > > log4j-1.2.17-16.el7_4.noarch > > yes, that's correct, but

Re: [CentOS] log4j cve

2021-12-14 Thread Simon Matter
> Hello Steve, > > Am 2021-12-14 14:14, schrieb Steve Clark: >> This is the standard version that comes with CentOS 7 and is the >> latest available as of a yum update just now. >> log4j-1.2.17-16.el7_4.noarch > > yes, that's correct, but it is abandoned nonetheless. > > According to the RPM's cha

Re: [CentOS] log4j cve

2021-12-14 Thread Mike Burger
On 2021-12-14 08:31, Steve Meier wrote: Hello Steve, Am 2021-12-14 14:14, schrieb Steve Clark: This is the standard version that comes with CentOS 7 and is the latest available as of a yum update just now. log4j-1.2.17-16.el7_4.noarch yes, that's correct, but it is abandoned nonetheless. Ac

Re: [CentOS] log4j cve

2021-12-14 Thread Steve Meier
Hello Steve, Am 2021-12-14 14:14, schrieb Steve Clark: This is the standard version that comes with CentOS 7 and is the latest available as of a yum update just now. log4j-1.2.17-16.el7_4.noarch yes, that's correct, but it is abandoned nonetheless. According to the RPM's change log, Red Hat

Re: [CentOS] log4j cve

2021-12-14 Thread Steve Clark via CentOS
On 12/14/21 8:07 AM, Steve Meier wrote: Hello Steve, Am 2021-12-14 13:42, schrieb Steve Clark via CentOS: Hi List, I see on CentOS 7 it has log4j-1.2.17... Is ok 2 use. I know the CVE was against 2.0 fwd but not knowing if something was backported to 1.2 ? Thanks, Steve log4j Version 1.2

Re: [CentOS] log4j cve

2021-12-14 Thread Steve Meier
Hello Steve, Am 2021-12-14 13:42, schrieb Steve Clark via CentOS: Hi List, I see on CentOS 7 it has log4j-1.2.17... Is ok 2 use. I know the CVE was against 2.0 fwd but not knowing if something was backported to 1.2 ? Thanks, Steve log4j Version 1.2 is definitely *NOT* OK to use. The Apache

[CentOS] log4j cve

2021-12-14 Thread Steve Clark via CentOS
Hi List, I see on CentOS 7 it has log4j-1.2.17... Is ok 2 use. I know the CVE was against 2.0 fwd but not knowing if something was backported to 1.2 ? Thanks, Steve -- Stephen Clark NetWolves Managed Services, LLC. Sr. Applications Architect Email Confidentiality Notice: The information contai