Skip to content

Commit

Permalink
minor changes to news
Browse files Browse the repository at this point in the history
Signed-off-by: Ceki Gulcu <ceki@qos.ch>
  • Loading branch information
ceki committed Dec 15, 2021
1 parent ca09c50 commit 6468696
Showing 1 changed file with 5 additions and 4 deletions.
9 changes: 5 additions & 4 deletions logback-site/src/site/pages/news.html
Expand Up @@ -73,8 +73,9 @@ <h3>14th of December, 2021, Release of version 1.2.8</h3>

<p class="highlight">We note that the vulnerability mentioned in
LOGBACK-1591 requires write access to logback's configuration file
as a prerequisite. <span class="green"><b>Please understand that log4Shell/CVE-2021-44228
and LOGBACK-1591 are of utterly different severity levels.</b></span></p>
as a prerequisite. <span class="green"><b>Please understand that
log4Shell/CVE-2021-44228 and LOGBACK-1591 are of different
severity levels.</b></span></p>


<p>&bull; In response to <a
Expand All @@ -93,8 +94,8 @@ <h3>14th of December, 2021, Release of version 1.2.8</h3>
<p>We note that the vulnerability mentioned in LOGBACK-1591
requires write access to logback's configuration file as a
prerequisite. Please understand that log4Shell/CVE-2021-44228 and
LOGBACK-1591 are of utterly different severity levels. A successul
RCE requires <em>all</em> of the following to be true:</p>
LOGBACK-1591 are of different severity levels. A successul RCE
requires <em>all</em> of the following conditions to be met:</p>

<ol>
<li>write access to logback.xml</li>
Expand Down

0 comments on commit 6468696

Please sign in to comment.