Fork me on GitHub
#pedestal
<
2021-12-11
>
orestis11:12:48

PSA: if you're using pedestal and log4j then you are vulnerable to the recently announced log4j vulnerability, since pedestal will log the path of a GET request.

🙏 1
ddeaguiar14:12:17

Based on http://slf4j.org/log4shell.html SLF4J It looks like if you use Logback you are ok. Pedestal services created through the service template use Logback.

orestis18:12:38

We switched recently from logback to log4j (can't remember the reasons any more) but luckily we patched everything before the floodgates opened

👍 1
ddeaguiar14:12:17

Based on http://slf4j.org/log4shell.html SLF4J It looks like if you use Logback you are ok. Pedestal services created through the service template use Logback.