Re: Query regarding impact due to Log4j Tool : Zero Day in Ubiquitous Under Active Attack (CVE-2021-44228)

2021-12-16 Thread Stefan Bodewig
Hi Apache Ant does not depend on log4j 2.x at all and never has. There is an optional Log4JListener that can be used to send Ant's logs through log4j 1.x that has been deprecated for quite some time now. Even if you still use it, logj 1.x is not affected by CVE-2021-44228 (but by several others,

Query regarding impact due to Log4j Tool : Zero Day in Ubiquitous Under Active Attack (CVE-2021-44228)

2021-12-16 Thread Banerjee, Saurabh (Pune)
Hi Team, We are using following jar provided your by. We want to ensure and know if it is impacted by "Apache Log4j Tool : Zero Day in Ubiquitous Under Active Attack (CVE-2021-44228)". If it's impacted please let us know about the security recommendation. To know we are looking for following ans