Skip to content

Log4j: Sanitize Log Parameters Created from User Input #1814

@lastzero

Description

@lastzero

Even though PhotoPrism is not directly affected by the Log4j debacle:

  • Log messages may contain parameters created from user input like photo & album titles
  • We should do our best to remove potentially problematic strings

More information on the Apache Log4j vulnerability:

Metadata

Metadata

Assignees

Labels

enhancementEnhancement or improvement of an existing featurereleasedAvailable in the stable releasesecurityImpact on server or browser security

Type

No type

Projects

Status

Release 🌈

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions