<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://okapiframework.org/wiki/index.php?action=history&amp;feed=atom&amp;title=About_the_Log4j2_vulnerabilities</id>
	<title>About the Log4j2 vulnerabilities - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://okapiframework.org/wiki/index.php?action=history&amp;feed=atom&amp;title=About_the_Log4j2_vulnerabilities"/>
	<link rel="alternate" type="text/html" href="http://okapiframework.org/wiki/index.php?title=About_the_Log4j2_vulnerabilities&amp;action=history"/>
	<updated>2026-04-22T19:12:33Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.2</generator>
	<entry>
		<id>http://okapiframework.org/wiki/index.php?title=About_the_Log4j2_vulnerabilities&amp;diff=897&amp;oldid=prev</id>
		<title>Mihnita: Created page with &quot; See  [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105 CVE-2021-45105], [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046 CVE-2021-45046], [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228 CVE-2021-44228], and the [https://logging.apache.org/log4j/2.x/security.html Log4j Security page].  After the recent weave of remote code execution vulnerabilities related to Apache Log4j we checked all the Okapi code, and that of all Okapi-relat...&quot;</title>
		<link rel="alternate" type="text/html" href="http://okapiframework.org/wiki/index.php?title=About_the_Log4j2_vulnerabilities&amp;diff=897&amp;oldid=prev"/>
		<updated>2021-12-24T21:37:29Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot; See  [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105 CVE-2021-45105], [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046 CVE-2021-45046], [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228 CVE-2021-44228], and the [https://logging.apache.org/log4j/2.x/security.html Log4j Security page].  After the recent weave of remote code execution vulnerabilities related to Apache Log4j we checked all the Okapi code, and that of all Okapi-relat...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&lt;br /&gt;
See &lt;br /&gt;
[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105 CVE-2021-45105],&lt;br /&gt;
[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046 CVE-2021-45046],&lt;br /&gt;
[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228 CVE-2021-44228],&lt;br /&gt;
and the [https://logging.apache.org/log4j/2.x/security.html Log4j Security page].&lt;br /&gt;
&lt;br /&gt;
After the recent weave of remote code execution vulnerabilities related to Apache Log4j we checked&lt;br /&gt;
all the Okapi code, and that of all Okapi-related projects hosted under https://bitbucket.org/okapiframework/:&lt;br /&gt;
&lt;br /&gt;
* [https://bitbucket.org/okapiframework/acorn/ acorn]&lt;br /&gt;
* [https://bitbucket.org/okapiframework/beagle/ beagle]&lt;br /&gt;
* [https://bitbucket.org/okapiframework/longhorn/ longhorn]&lt;br /&gt;
* [https://bitbucket.org/okapiframework/longhorn-js-client/ longhorn-js-client]&lt;br /&gt;
* [https://bitbucket.org/okapiframework/maven-repo/ maven-repo]&lt;br /&gt;
* [https://bitbucket.org/okapiframework/okapi/ okapi]&lt;br /&gt;
* [https://bitbucket.org/okapiframework/okapi-integration-tests/ okapi-integration-tests] (DEPRECATED!)&lt;br /&gt;
* [https://bitbucket.org/okapiframework/okapi-linguistic-tools/ okapi-linguistic-tools]&lt;br /&gt;
* [https://bitbucket.org/okapiframework/okapi-validation-tools/ okapi-validation-tools]&lt;br /&gt;
* [https://bitbucket.org/okapiframework/olifant/ olifant]&lt;br /&gt;
* [https://bitbucket.org/okapiframework/omegat-plugin/ omegat-plugin]&lt;br /&gt;
* [https://bitbucket.org/okapiframework/quest/ quest]&lt;br /&gt;
* [https://bitbucket.org/okapiframework/sandbox/ sandbox]&lt;br /&gt;
* [https://bitbucket.org/okapiframework/srx-repository/ srx-repository]&lt;br /&gt;
* [https://bitbucket.org/okapiframework/xliff-toolkit/ xliff-toolkit] (DEPRECATED!)&lt;br /&gt;
&lt;br /&gt;
'''None of that code depends on &amp;lt;code&amp;gt;log4j&amp;lt;/code&amp;gt;, directly or indirectly.'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''So we are not affected.'''&lt;br /&gt;
&lt;br /&gt;
'''&amp;lt;span style=&amp;quot;color: red;&amp;quot;&amp;gt;But it does not mean you are safe and have nothing to do.&amp;lt;/span&amp;gt;'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''&amp;lt;span style=&amp;quot;color: red;&amp;quot;&amp;gt;If a product using Okapi binds &amp;lt;code&amp;gt;log4j&amp;lt;/code&amp;gt; with SLF4J, then they are at risk, but it is not because of Okapi.&amp;lt;/span&amp;gt;'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''&amp;lt;span style=&amp;quot;color: red;&amp;quot;&amp;gt;They should apply the log4j updates as necessary, or switch to another logging framework.&amp;lt;/span&amp;gt;'''&lt;br /&gt;
&lt;br /&gt;
The Okapi Framework uses [https://www.slf4j.org/ SLF4J] for logging.&lt;br /&gt;
&lt;br /&gt;
That is an abstraction for various logging frameworks (e.g. &amp;lt;code&amp;gt;java.util.logging&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;logback&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;log4j&amp;lt;/code&amp;gt;)&lt;br /&gt;
allowing developers (or even end users) to plug in the desired logging framework at deployment time.&lt;br /&gt;
&lt;br /&gt;
Okapi itself does not require an update, as it does not come &amp;quot;out of the box&amp;quot; with any one logging framework.&lt;br /&gt;
&lt;br /&gt;
Some of our projects use Okapi to build applications that bind to a logging framework:&lt;br /&gt;
&lt;br /&gt;
* The Okapi binaries bind &amp;lt;code&amp;gt;slf4j&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;[https://logback.qos.ch/ logback]&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Acorn binds with &amp;lt;code&amp;gt;log4j12&amp;lt;/code&amp;gt;, which is not affected by the recent disclosures&amp;lt;br /&amp;gt;(but &amp;lt;code&amp;gt;log4j12&amp;lt;/code&amp;gt; is unmaintained, deprecated, and has its own share of problems)&lt;/div&gt;</summary>
		<author><name>Mihnita</name></author>
	</entry>
</feed>