Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Log4j vulnernerability in jira apps

Ramakrishna Grandhi
Contributor
December 13, 2021

Hi, we've a jira server app and its .jar file. It has a dependency on log4j 1.2.6 indirectly i.e. we dont have the ref in pom.xml but one of the dependencies has it. Can someone advise on how to make this transitive dependency to latest log4j?

2 answers

1 accepted

1 vote
Answer accepted
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
June 23, 2014

Yes. Groovy really is very powerful because it can use most of the internals, and should only ever be used by administrators (because you can, in theory, trust them to know how to avoid doing any damage with it)

You may find it safer to let them work with a dev/test system as an admin, and then promote their work when you've proved it's ok.

0 votes
Ryan O Sullivan
June 23, 2014

Thanks Nic, thought as much

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events