Log4j2 issue

I have this mentioned 2 jar file...
1.)log4j-1.2.17.jar
2.)apache-log4j-extras-1.2.17.jar

does this 2 jar affect any vulnerability? and yes so what changes required from our end please suggest.

Dears,
Are there any vulnerability issues in log4j-1.2.17.jar ?

Please read the security announcetment that is pinned in the first page of the forum, everything about the log4j vulnerabilities affecting the stack or not and the ways to mitigates are listed in the topic.

1 Like