Page 1 of 1

Log4j Vulnerability

PostPosted:Thu Dec 16, 2021 2:10 pm
by MrAP
Hi,

is the CE Version 6.3.10 vulnerable to Log4j ??

Re: Log4j Vulnerability

PostPosted:Sat Dec 18, 2021 9:50 am
by jllort
Most or all version 6.3.x are not vulnerable to this bug because OpenKM it uses logback. If you have in your tomcat folder a file named logback.xml should not be worried about it.

However upgrade to the latest version is a good practice.