Re: Log4j upgrade in spark binary from 1.2.17 to 2.17.1

2022-01-31 Thread Sean Owen
(BTW you are sending to the Spark incubator list, and Spark has not been in incubation for about 7 years. Use user@spark.apache.org) What update are you looking for? this has been discussed extensively on the Spark mailing list. Spark is not evidently vulnerable to this. 3.3.0 will include log4j 2

RE: Log4j upgrade in spark binary from 1.2.17 to 2.17.1

2022-01-31 Thread KS, Rajabhupati
Hi Team , Is there any update on this request ? We did see Jira https://issues.apache.org/jira/browse/SPARK-37630 for this request but we see it closed . Regards Raja From: KS, Rajabhupati Sent: Sunday, January 30, 2022 9:03 AM To: u...@spark.incubator.apache.org Subject: Log4j upgrade in spa

Re: Log4j upgrade in spark binary from 1.2.17 to 2.17.1

2022-01-29 Thread Sean Owen
This has been discussed extensively on this list. See the archives. TL;DR is current releases do not appear to be vulnerable. But 3.3.0 will move to log4j 2 anyway On Sat, Jan 29, 2022, 9:42 PM KS, Rajabhupati wrote: > Hi Team, > > We were checking for log4j upgrade in Open source spark version