Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Log4j-api isn't vulnerable and the slf4j-log4j bridge depends on it. Log4j-core is. All of our internal security scanners failed to make this distinction so we had to post filter ourselves.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: