Skip to content

remove use of log4jv1 - no longer supported and has security vulnerabilities #3819

@pjfanning

Description

@pjfanning

BUG REPORT

Related to but separate from #3816

https://github.com/apache/rocketmq/blob/develop/pom.xml#L582

log4j v1 is not supported (EOL) and numerous CVEs are open against it

  • ideally use log4jv2 instead
  • reload4j is a drop-in replacement for log4jv1 - but ideally, rocketmq should standardise on one log framework and log4jv2 is used in rocketmq too

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions