-
Notifications
You must be signed in to change notification settings - Fork 3.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
HBASE-26557 log4j2 has a critical RCE vulnerability #3933
Conversation
🎊 +1 overall
This message was automatically generated. |
And I suggest that we add -Dlog4j2.formatMsgNoLookups=true in the start scripts to disable JNDI completely, we do not need this feature in HBase, typically. |
Added the parameter to the start script. |
🎊 +1 overall
This message was automatically generated. |
💔 -1 overall
This message was automatically generated. |
🎊 +1 overall
This message was automatically generated. |
🎊 +1 overall
This message was automatically generated. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
+1. According to the CVE, the formatMsgNoLookups=true flag is only required if NOT upgrading to 2.15, but I see no harm in being explicit since we don't use the JNDI lookup anyway.
💔 -1 overall
This message was automatically generated. |
https://issues.apache.org/jira/browse/HBASE-26557