Closed
Description
Hi,
can somebody please confirm that the image confluentinc/cp-kafka:6.0.1
is NOT affected by the log4j vulnerability CVE-2021-44228
?
If I checked correctly, it uses a custom log4j version based on v1.2.17 (https://github.com/confluentinc/kafka/blob/9c1fbb3db1e0d69d09f165b3b9861fc984ad1a62/gradle/dependencies.gradle#L78), which is not included in the list of affected versions. Still, I want to make sure I am right here.
Thank you!
Metadata
Metadata
Assignees
Labels
No labels