Profile

Martin Rupp

Siemens AG

Contact Details

Siemens AG

My Content

1 to 3 of 3 total
Posted By Martin Rupp 12-16-2021 03:45
Found In Egroup: Pentaho
\ view thread
Matt - my colleagues have created the scanner.  Log4j 1.x had reached end of life! It is a very old lib with many security issues.  (e.g.: https://www.cvedetails.com/cve/CVE-2019-17571/) Acc. to the German BSI report log4j 1.x must also be replaced by log4j 2.16 (not simple to do it, because ...
Posted By Martin Rupp 12-15-2021 11:56
Found In Egroup: Pentaho
\ view thread
I don't know if spoon uses all of this log4j libraries. But this is not important. The management don't want that log4j libs < version 2.16 are present. Log4j 2 is not compatible to log4j 1. But there is a mode to simulate log4j 1 with some constraints and risks. https://logg ...
Posted By Martin Rupp 12-15-2021 05:46
Found In Egroup: Pentaho
\ view thread
We have now a scanner for log4j in the company. It has found these locations in PDI 9.2 Community Edition: D:\Tools\Pentaho Data Integration\pdi-ce-9.2.0.0-290\data-integration\lib\apache-log4j-extras-1.2.17.jar contains Log4J-1.x 1.2.17 __END_OF_LIFE_VERSION__ D:\Tools\Pentaho Data I ...