Skip to content

Conversation

@dabrt
Copy link
Contributor

@dabrt dabrt commented Apr 20, 2022

Question Answer
JIRA Ticket IBX-1699
Versions 3.3 and up

@dabrt dabrt requested review from barw4 and glye April 20, 2022 16:02
@dabrt dabrt merged commit 2008eea into master Apr 21, 2022
@dabrt dabrt deleted the IBX-1699 branch April 21, 2022 07:58
dabrt added a commit that referenced this pull request Apr 21, 2022
dabrt added a commit that referenced this pull request Apr 21, 2022
dabrt added a commit that referenced this pull request Apr 21, 2022
Copy link
Contributor

@glye glye left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

JDK should also be upgraded, to 11 imho, see https://developers.ibexa.co/security-advisories/cve-2021-44228-log4j-vulnerability

I'm not sure this qualifies as a requirement, but the Log4j bug that affected Elasticsearch was only exploitable with JDK 8. 9 is unsupported. 11 is a supported LTS release, it would be good to recommend this. 17 is a newer LTS, but I hear we're not quite compatible with that, so 11 is best. https://www.oracle.com/java/technologies/java-se-support-roadmap.html

@glye
Copy link
Contributor

glye commented Apr 27, 2022

Follow up PR on Java: #1601

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants