
Log4J Security Vulnerability & Pyramid
There has been a critical notification of a potentially serious vulnerability in the Apache Log4J Java library used extensively in many Java applications world-wide, including Pyramid.
The versions of the Log4J library that are affected by this critical issue are found in "Log4J2" for versions 2.0 through 2.14.1 (as documented in CVE-2021-44228 and described here and elsewhere on the internet).
Pyramid, however, uses Log4J 1.2.17 which does NOT contain this problem and is therefore not exposed to this vulnerability.
In the next release (2020.22) we will upgrade this component to a new version and correct any issues found in older versions of the Log4J component (which are not considered critical).
DEC-23-2021 :SEE THE UPDATED POSTING PROVIDING UPDATED REMEDIES FOR THE LOG4J VULNERABILITY
-
You might want to publish that here as well: https://github.com/NCSC-NL/log4shell/tree/main/software#log4j-overview-related-software
-
PLEASE SEE THE UPDATED POSTING PROVIDING UPDATED REMEDIES FOR THE LOG4J VULNERABILITY and details on the new 2020.22 RELEASE