Effect of log4j vulnerability on wildfly-11.0.0-final

284 Views Asked by At

I am using wildfly-11.0.0-final. I can see the log4j-jboss-logmanager jar has a log4j 1.2.16 dependency. Will it be affected? How to mitigate this?

1

There are 1 best solutions below

0
ehsavoie On

If you are not using the JMSAppender you shouldn't be exposed if I understand https://www.wildfly.org/news/2021/12/13/Log4j-CVEs/ correctly.