<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>about Apache Log4j Security Vulnerabilities</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121304502" />
  <subtitle>about Apache Log4j Security Vulnerabilities</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121304502</id>
  <updated>2026-04-04T00:58:55Z</updated>
  <dc:date>2026-04-04T00:58:55Z</dc:date>
  <entry>
    <title>RE: about Apache Log4j Security Vulnerabilities</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121304881" />
    <author>
      <name>Tomáš Polešovský</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121304881</id>
    <updated>2021-12-23T07:02:47Z</updated>
    <published>2021-12-21T10:03:11Z</published>
    <summary type="html">&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;Please see &lt;a href="https://liferay.dev/blogs/-/blogs/log4j2-vulnerability-fixing-the-jar"&gt;https://liferay.dev/blogs/-/blogs/log4j2-vulnerability-fixing-the-jar&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Please don't forget to fix all log4j-core JAR files in the classpath.&lt;/p&gt;
&lt;p&gt;Thank you.&lt;/p&gt;
&lt;p&gt;- Tomas&lt;/p&gt;</summary>
    <dc:creator>Tomáš Polešovský</dc:creator>
    <dc:date>2021-12-21T10:03:11Z</dc:date>
  </entry>
  <entry>
    <title>about Apache Log4j Security Vulnerabilities</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121304501" />
    <author>
      <name>Scarletake Bwi</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121304501</id>
    <updated>2021-12-22T07:24:31Z</updated>
    <published>2021-12-21T03:01:03Z</published>
    <summary type="html">&lt;p&gt;hi &lt;/p&gt;
&lt;p&gt;i am using liferay ce 7.4.3.4&lt;/p&gt;
&lt;p&gt;it's about &lt;a
    href="https://logging.apache.org/log4j/2.x/security.html"&gt;Log4j2 vulnerability.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;i do not understand, it should happen when using log4j2, but in
  &amp;lt;liferay
  home&amp;gt;/tomcat-9.0.53/webapps/ROOT/WEB-INF/shieded-container-lib, i
  only see log4j-1.2.jar, lkog4j-api.jar and log4j-core.jar&lt;/p&gt;
&lt;p&gt;
  &lt;strong&gt;may i just replace the jar with new download from apache and
    fix this issue?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;i try download log4j 2.17.0 and replace  3 jras in&lt;/p&gt;
&lt;p&gt;&amp;lt;liferay home&amp;gt;/tomcat-9.0.53/webapps/ROOT/WEB-INF/shieded-container-lib&lt;/p&gt;
&lt;p&gt;and&lt;/p&gt;
&lt;p&gt;&amp;lt;liferay home&amp;gt;/elasticsearch-sidecar/7.10.2/lib, restart
  server, it's looks fine. &lt;/p&gt;
&lt;p&gt;and i also
  update com.liferay.portal.bootstrap.jar/META-INF/system.packages.extra.mf,
  change all log4j to 2.17.0&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;but i find there still have log4j-api-2.11.1.jar
  and log4j-core-2.11.1.jar in &lt;/p&gt;
&lt;p&gt;&amp;lt;liferay home&amp;gt;\osgi\state\org.eclipse.osgi\607\0\.cp\lib&lt;/p&gt;
&lt;p&gt;it's looks like the jar be download by maven, how can i fix this?&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;thank you in advance.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;</summary>
    <dc:creator>Scarletake Bwi</dc:creator>
    <dc:date>2021-12-21T03:01:03Z</dc:date>
  </entry>
</feed>
