You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Thanks for bringing this up.
Will provide an update as soon as possible.
However, in order to exploit Log4shell here, you'd need access to the database the cli is run against and create a test with a malicious name.
Possible, but very unlikely.
How would you see the log4j issue to be exploited in this software?
We will definitely update the log4j library or remove it at some point when working on new features/bugfixes for cli.
I'm not sure however if there is real value in fixing it by itself.
Activity
pesse commentedon Feb 4, 2022
Thanks for bringing this up.
Will provide an update as soon as possible.
However, in order to exploit Log4shell here, you'd need access to the database the cli is run against and create a test with a malicious name.
Possible, but very unlikely.
drumbeg commentedon Mar 3, 2022
Any update on the log4j issue?
jgebal commentedon Mar 13, 2022
How would you see the log4j issue to be exploited in this software?
We will definitely update the log4j library or remove it at some point when working on new features/bugfixes for cli.
I'm not sure however if there is real value in fixing it by itself.
Does it block you in any way at the moment?
Update dependencies