Skip to content

巡云轻论坛系统5.5

Choose a tag to compare

@diyhi diyhi released this 29 Nov 02:04
· 29 commits to master since this release

bbs-5.5.zip是5.5安装包,更新详细内容请查看官网

bbs-5.4to5.5.zip是5.4升级到5.5升级包,升级详细内容请查看官网。

受2021年12月9日的log4j2组件远程代码执行漏洞影响,需要替换旧版log4j2的jar包修复漏洞
1、解压安装包后,找到 \WEB-INF\lib\ 目录,将里面的以下文件删除
log4j-api-2.11.0.jar
log4j-core-2.11.0.jar
log4j-jcl-2.11.0.jar
log4j-web-2.11.0.jar

2、到maven仓库下载新的log4j2组件放到 \WEB-INF\lib\ 目录
https://repo1.maven.org/maven2/org/apache/logging/log4j/log4j-api/2.17.0/log4j-api-2.17.0.jar
https://repo1.maven.org/maven2/org/apache/logging/log4j/log4j-core/2.17.0/log4j-core-2.17.0.jar
https://repo1.maven.org/maven2/org/apache/logging/log4j/log4j-jcl/2.17.0/log4j-jcl-2.17.0.jar
https://repo1.maven.org/maven2/org/apache/logging/log4j/log4j-web/2.17.0/log4j-web-2.17.0.jar