I see stash-java-client-core latest version uses log4j 1.X.
I am aware log4j 1.X is not vulnerable to the Zero Day vulnerability but still I prefer to upgrade to 2.17
Has anyone found how to this? Is there any work around to make sure log4j 1.X is not being used? I see it is a compile dependency which implies stash-java-client-core requires log4j to work.
Any answer would be really helpful. Thanks
Hi
I asked same question from support and i did get this answer:
I hope it will help You also.
With best
Urmo
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.