Re: heads up when running roller from master branch

Dave <[email protected]> Sat, 11 Dec 2021 17:05:01 -0500
Newsgroups gmane.comp.java.roller.devel
Message-ID <CAF1aazDdtpSvQ8HX71jU5ZHB6RgTZ-HvNPBFq2YE3Vfjt3sdqA@mail.gmail.com>
Nice! I did not remember that 6.0.2 still used Log4j 1.

On Sat, Dec 11, 2021 at 4:20 PM Michael Bien <[email protected]> wrote:

> Hello Everyone,
>
> Just a heads up in case you are building and running apache roller from
> master, please rebuild your instance with the latest changes.
>
> It contains an important dependency update
> (https://github.com/apache/roller/pull/106) for log4j 2 which suffered
> from a RCE security vulnerability, which was fixed in the latest version.
>
> Apache Roller 6.0.2 (latest release) should not be affected by this
> particular vulnerability since it still uses the old log4j 1 library.
>
> best regards,
>
> michael
>
>