#1
|
||||
|
||||
CVE-2021-44228, log4j, JDownloader is NOT affected
CVE-2021-44228, log4j, JDownloader is NOT affected
We just want to let you know that neither JDownloader nor any other of our projects make use of log4j and thus are not affected by this security vulnerability. Edit: 15.12.2021 Due to a question on Reddit, we would like to get a bit more into detail: Neither JDownloader itself nor its libraries/dependencies use or contain log4j. This includes all executable code in - JDownloader.jar - Core.jar - All dependencies in the /libs/ folder - All extensions in the /extensions/ folder - All plugins in jd/plugins/ folders If you want to get sure: Executable code is stored in *.jar files ( And the plugin folders) You can open these jar files with any ZIP extractor. As long as you don't find any strings or files that start with/contain org.apache.log4j or org.apache.logging.log4j we are fine.
__________________
Last edited by Jiaz; 15.12.2021 at 15:31. |
#2
|
||||
|
||||
1984 was such a great year =]
__________________
raztoki @ jDownloader reporter/developer http://svn.jdownloader.org/users/170 Don't fight the system, use it to your advantage. :] |
#3
|
|||
|
|||
(sorry, bad english)
JDownloader\jre\lib\resources.jar In this JAR-file are some Strings with "log4j". JCEAlias CDATA #IMPLIED ><!ELEMENT Log4J EMPTY><!ATTLIST Log4J configFile CDATA 'data/log4j.xml' > But after unpack with WinRAR, there are NO log4j-files in the resources-folder. I dont know the format of JARs and I dont know Java. Any problem because the strings "log4j" in resources.jar? |
#4
|
||||
|
||||
Quote:
About Jar-files: See the first post
__________________
Last edited by coalado; 15.12.2021 at 12:07. |
#5
|
|||
|
|||
Very fine !
|
#6
|
|||
|
|||
Thanks for the answers. But is the Java Version "Java SE Embedded 8" Version 1.8.0_211-0050 installed on my Synology for JDownloader affected?
Thanks a lot! |
#7
|
||||
|
||||
@Carmageddon: The issue is about the log4j library and its usages as dependency in applications and not about any java version.
__________________
JD-Dev & Server-Admin |
Thread Tools | |
Display Modes | |
|
|