Eclair not vulnerable to Log4J 2.1x remote execution issues. #2100
n1bor
started this conversation in
Node operators
Replies: 2 comments 1 reply
-
Agreed, we tweeted that eclair wasn't impacted: https://twitter.com/acinq_co/status/1469678544989179917 |
Beta Was this translation helpful? Give feedback.
0 replies
-
To mitigate this type of attack would the following be possible:
Obviously 3 is possible. And 1 we can do now (I already do). So would just need a way to also do 3. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
It is using logback that is based off log4j version 1.x
http://logback.qos.ch/
Anyone disagree?
Just for everyone reference:
https://nvd.nist.gov/vuln/detail/CVE-2021-44228
this is the issue that does NOT effect Eclair.
Beta Was this translation helpful? Give feedback.
All reactions