Prisma Alert #6507
Unanswered
sreejesh-radhakrishnan-db
asked this question in
Q&A
Prisma Alert
#6507
Replies: 2 comments 5 replies
-
Log4j2 had multiple CVEs over several weeks. IIRC, some of them were fixed in 0.26.1, some of them in later versions only. So you might need to upgrade. In the thread dedicated to the Log4j2 CVE there might be more details about which CVE is fixed where. The Log4j1 CVEs are part of Apache Kafka and need to be addressed there (there is an ongoing work on that). |
Beta Was this translation helpful? Give feedback.
5 replies
-
thanks @scholzj |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
We are running Operator version 0.26.1 and Kafka 0.26.1-kafka2.8.0 , we are onboarded to PRISMA alerts and following issues was raised with Critical or High Severity. Please can you help us why these are raised I thought all the log4j issues was fixed on 0.26.1 . For non log4j issues If these are genuine ones will there be a plan to fix these in any up coming release?
<style> </style>Beta Was this translation helpful? Give feedback.
All reactions