We are using Jira v7.13.13, and we see number of folders using the log4j-1.X jar files which have already reached end of life since year 2016.
Below are few of the folders with these jar files:
/opt/atlassian/jira/lib/log4j-1.2.16.jar
/opt/devops/atlassian-jira-software-7.13.11-standalone/lib/log4j-1.2.16.jar
/var/atlassian/application-data/jira/plugins/.osgi-plugins/felix/felix-cache/bundle73/version0.0/jira-projects-plugin-4.5.35.jar-embedded/META-INF/lib/log4j-1.2.16.jar
For now, we have mitigated by removing the JMSAppender.class from these jar files. But since this is using EOL product, we are advised to migrate it to log4j-2.X versions. Please advise and provide us the steps for these.
Thanks
Daljinder Singh
Mobile number: +65-87271801
Hi @mayank ashok ,
I'm not sure if upgrading is warranted. If you like to follow the status of upgrading the version, please follow this ticket.
https://jira.atlassian.com/browse/JRASERVER-62838
IF the concern is vulnerability, then you just need to be on Atlassian maintain fork version. Please see link for details:
Thanks,
Ben
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.