Vulnerabilities in Airbyte | Apache Log4j #40258
-
We have Vulnerabilities in Airbyte in Apache Log4j ( CVE-2021-4104) and how to close this Vulnerabilities . Airbyte version : 0.59.0 |
Beta Was this translation helpful? Give feedback.
Replies: 4 comments 2 replies
-
@wennergr can you check this and if the depedency was updated in latest version? |
Beta Was this translation helpful? Give feedback.
-
Hey @Nasser506, thank you for the report. We are looking into resolving the issue. Were you able to use the log4j vulnerability to compromise confidentiality, integrity, or availability? |
Beta Was this translation helpful? Give feedback.
-
Dear @marcosmarxm , Do you have any updates? Does the latest Airbyte version include the new version of Apache Log4j? |
Beta Was this translation helpful? Give feedback.
-
Hey @Nasser506, The log4j vulnerability you reference was in the destination-s3 connector, which has since been patched (version 0.6.4 in dockerhub). Log4j was imported as a transitive dependency from a library that was not in use, so the vulnerability did not affect us. |
Beta Was this translation helpful? Give feedback.
Hey @Nasser506,
The log4j vulnerability you reference was in the destination-s3 connector, which has since been patched (version 0.6.4 in dockerhub).
Log4j was imported as a transitive dependency from a library that was not in use, so the vulnerability did not affect us.