Profile

Matt Kynaston

Claritum Ltd

Contact Details

Claritum Ltd

My Content

1 to 3 of 3 total
Posted By Matt Kynaston 12-15-2021 15:17
Found In Egroup: Pentaho
\ view thread
Martin - good catch with the stuff under system/karaf/caches. I'd scanned a clean build so it wasn't picking those up. For anyone updating things in-place, you'll definitely want to remove that caches directory or you'll still have vulnerable versions of the library in use. The caches directory will ...
Posted By Matt Kynaston 12-13-2021 17:33
Found In Egroup: Pentaho
\ view thread
I'm on Pentaho BI server 9.1. This ships log4j 2.8.2 hidden in pentaho-solutions/system/karaf/system/org/ops4j/pax/logging/pax-logging-log4j2/1.10.2/pax-logging-log4j2-1.10.2.jar. I have no idea where that might be used, but the only mitigation I can find is to remove JndiLookup.class from the jar ...
Posted By Matt Kynaston 12-13-2021 06:29
Found In Egroup: Pentaho
\ view thread
You do not have permission to view this page. :-( Any chance of reposting the content here? ------------------------------ Matt Kynaston Chief Technology Officer Claritum Ltd ------------------------------