Re: [VOTE] KIP-719: Add Log4J2 Appender

2021-06-11 Thread Boojapho O
+1 (non-binding) On 2021/06/09 15:31:13, Dongjin Lee wrote: > Bumping up the voting thread. > > Please note that today is the KIP freeze day. > > Thanks, > Dongjin > > On Mon, Jun 7, 2021 at 9:28 PM Dongjin Lee wrote: > > > Bumping up the voting thread. > > > > > > As a reminder: Please not

Re: [DISCUSS] KIP-719: Add Log4J2 Appender

2021-06-11 Thread Boojapho O
Continuing to use log4j would leave several known security vulnerabilities in Apache Kafka, including https://nvd.nist.gov/vuln/detail/CVE-2019-17571. The Apache log4j team will not fix this vulnerability and is urging an upgrade to log4j2. See https://logging.apache.org/log4j/1.2/ for further