Skip to content

Update Java agent to use new version of log4j 2 #605

@kbford56

Description

@kbford56

Is your feature request related to a problem? Please describe.

A well-publicized vulnerability has been discovered with certain versions of the log4j 2 framework. Some references:

Feature Description

Need to publish updated maint releases for the following major agent versions (these are still under support):

  • Java Agent 7.4.1
  • Java Agent 6.5.1
  • Java Agent 7.4.2
  • Java Agent 6.5.2
  • Java Agent 7.4.3
  • Java Agent 6.5.3

Describe Alternatives

A workaround to the issue has been described, to disable logging by setting the log level to off.
See security bulletin NR21-03 for the latest mitigation actions.

Additional context

Older versions of the Java Agent that are not currently supported will not be updated, in alignment with our published EOL policy.

Priority

Critical

Metadata

Metadata

Labels

GTSEThere is an associated support escalation with this issue.

Type

No type

Projects

Status

No status

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions