Liferay DXP 7.2 Log4j

Abhay Gupta, modified 3 Years ago. New Member Posts: 20 Join Date: 3/16/20 Recent Posts

Hi All

We are using Liferay DXP 7.2. Nessus scan is reporting an outdated version of Log4j in the osgi state folder. I am not sure on how to remove this jar. this is the location

user_projects\domains\osgi\state\org.eclipse.osgi\422\0\.cp\lib\log4j-core-2.11.2.jar

I know DXP 7.2 is not impacted but our security team wants us to update this.

Can you please help us on the steps needed to update the jar version.

Thanks