<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>Liferay DXP 7.2 Log4j</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121456202" />
  <subtitle>Liferay DXP 7.2 Log4j</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121456202</id>
  <updated>2026-04-07T20:13:15Z</updated>
  <dc:date>2026-04-07T20:13:15Z</dc:date>
  <entry>
    <title>Liferay DXP 7.2 Log4j</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121456201" />
    <author>
      <name>Abhay Gupta</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121456201</id>
    <updated>2022-06-27T18:52:03Z</updated>
    <published>2022-06-27T18:52:03Z</published>
    <summary type="html">&lt;p&gt;Hi All&lt;/p&gt;
&lt;p&gt;We are using Liferay DXP 7.2. Nessus scan is reporting an outdated
  version of Log4j in the osgi state folder. I am not sure on how to
  remove this jar. this is the location&lt;/p&gt;
&lt;p&gt;user_projects\domains\osgi\state\org.eclipse.osgi\422\0\.cp\lib\log4j-core-2.11.2.jar&lt;/p&gt;
&lt;p&gt;I know DXP 7.2 is not impacted but our security team wants us to
  update this.&lt;/p&gt;
&lt;p&gt;Can you please help us on the steps needed to update the jar version.&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;</summary>
    <dc:creator>Abhay Gupta</dc:creator>
    <dc:date>2022-06-27T18:52:03Z</dc:date>
  </entry>
</feed>
