I am using, kafka-avro-serializer and I could not locate which version of log4j it uses internally for logging, so, I was wondering if it is impacted by the security vulnerability CVE-2021-44228? Also, which version does it use?
I checked the FAQs and the thread but I couldn't find anything specific to kafka-avro-serializer.
If the vulnerability depends on the version of kafka-avro-serializer being used, then, would really appreciate how I can identify that.
Thank you.
Hi Santosh,
Good afternoon, and thank you for raising this on Atlassian Community.
I have never heard of kafka-avro-serializer personally,, but I looked into it, and I believe you might be referring to a product called "Confluent" instead of "Confluence."
https://www.confluent.io/confluent-cloud/?_ga=2.103147848.992168864.1639579152-521892196.1639579152
Does that seem to be what you're using? If so, I recommend contacting Confluent instead:
https://www.confluent.io/contact
I hope that helps, but let me know if you have any questions.
Shannon | Atlassian Cloud Support
Hi Shannon. Oh, my bad. Didn't realize that. Thanks for clearing that up.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Santosh,
It's no problem. I can understand since the names are really close. 🙂
Take care, and I hope you have a nice rest of your day.
Shannon | Atlassian Cloud Support
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.