Eclair not vulnerable to Log4J 2.1x remote execution issues. #2100
n1bor
started this conversation in
Node operators
Replies: 2 comments 1 reply
-
Agreed, we tweeted that eclair wasn't impacted: https://twitter.com/acinq_co/status/1469678544989179917 |
Beta Was this translation helpful? Give feedback.
0 replies
-
To mitigate this type of attack would the following be possible:
Obviously 3 is possible. And 1 we can do now (I already do). So would just need a way to also do 3. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
It is using logback that is based off log4j version 1.x
http://logback.qos.ch/
Anyone disagree?
Just for everyone reference:
https://nvd.nist.gov/vuln/detail/CVE-2021-44228
this is the issue that does NOT effect Eclair.
Beta Was this translation helpful? Give feedback.
All reactions