riemann/riemann

Which versions of riemann, if any, are susceptible to log4shell (log4j vulnerability)?

ahungry opened this issue · 1 comments

http://slf4j.org/log4shell.html

Which versions of riemann may be impacted? For instance, riemann-0.3.1 uses slf4j-over-log4j, which the linked page notes could be exposed to the log4shell issue.

Thanks for reaching out. Riemann is not vulnerable - we use Logback as the backend to slf4j - which isn't vulnerable to the issue.