Log4j issue

[email protected]
Newsgroups gmane.comp.jakarta.log4j.user,gmane.text.xml.xalan.devel
Message-ID <20211220082424.Horde.u0YPSLrDr1NiuHJ0ngjA2I1@webmail.virtualcdc.com>
Dear team
Hi.

According to Log4j vulnerability as I know one of the solution was  
remove JndiLookup.class file from log4j-core-*.jar file .

But now we see other vulnerability :

upgrade to 2.17 or
Otherwise, in the configuration, remove references to Context Lookups  
like ${ctx:loginId} or $${ctx:loginId} where they originate from  
sources external to the application such as HTTP headers or user input.

1- Is that your mean remove class file (JndiLookup.class) cannot help us ?
2- Would you please say how we can do this on Linux systems ?
in the configuration, remove references to Context Lookups like  
${ctx:loginId} or $${ctx:loginId} where they originate from sources  
external to the application such as HTTP headers or user input.

Best regards.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.