This is the Git source repo for unofficial Docker images of WSO2IS with Lo4j CVE-2021-45046 and CVE-2021-44228 patched.
Docker images for WSO2IS with Lo4j CVE-2021-45046 and CVE-2021-44228 patched
The CVEs were patched by deleting the file org/apache/logging/log4j/core/lookup/JndiLookup.class from affected jars, per the recommended mitigations listed on the Log4j Security page.
If you're already using WSO2IS images, simply substitute codebling/wso2is in place of wso2/wso2is and keep the same version tag.
If you're not already using WSO2IS images, consult the documentation for the WSO2IS images
All images are based on (FROM) WSO2IS images and all tags match those ones.
latest, 5.11.0, 5.10.0, 5.9.0, 5.8.05.9.0-centos7, 5.10.0-centos75.9.0-alpine3.10, 5.10.0-alpine3.11, 5.8.0-alpine3.10
See the official WSO2 website for more info.