<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Qlik Talend Data Integration: CVE-2020-9493 – Apache Log4j v1.2.17.0 Detected After SecOps Scan in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Talend-Data-Integration-CVE-2020-9493-Apache-Log4j-v1-2-17/ta-p/2520960</link>
    <description>&lt;P&gt;After a recent scan by SecOps team, the same vulnerable files that were previously flagged have reemerged within the system. The vulnerability is rated as critical:&lt;/P&gt;
&lt;P&gt;CVE-2020-9493 – Apache Log4j v1.2.17.0&lt;BR /&gt;Reference: NVD - CVE-2020-9493&lt;/P&gt;
&lt;P&gt;The affected files have been identified in the following locations:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;lt;Studio_Home&amp;gt;/addons/scripts/lucene_migration_tool/lib/lucene-4-8.0.0.jar&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;Studio_Home&amp;gt;/addons/scripts/lucene_migration_tool/lib/lucene-8-8.0.0.jar&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Cause&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;This issue arises solely when Talend Studio is installed via the Talend Installer, resulting in the creation of the 'lucene_migration_tool' folder, which contains lucene-4-8.0.0.jar and lucene-8-8.0.0.jar. These Jar files utilize Apache Log4j version 1.2.17.0.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Please manually delete the 'lucene_migration_tool' folder from the directory located at '&amp;lt;Studio_Home&amp;gt;/addons/scripts/'. This migration tool is only useful when creating an index from a version lower than Talend Studio 7.2. For further details, please read this documentation &lt;A href="https://help.qlik.com/talend/en-US/release-notes/8.0/data-quality-migration" target="_self"&gt;page&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Kindly know that the&amp;nbsp;'lucene_migration_tool' folder will not be created in the new version of Talend Installer.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Internal Investigation ID(s)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;SUPPORT-3978&lt;/P&gt;
&lt;P&gt;TINSTL-238&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Talend Studio&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Fri, 20 Jun 2025 01:04:44 GMT</pubDate>
    <dc:creator>FangZhen_TAO</dc:creator>
    <dc:date>2025-06-20T01:04:44Z</dc:date>
    <item>
      <title>Qlik Talend Data Integration: CVE-2020-9493 – Apache Log4j v1.2.17.0 Detected After SecOps Scan</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Talend-Data-Integration-CVE-2020-9493-Apache-Log4j-v1-2-17/ta-p/2520960</link>
      <description>&lt;P&gt;After a recent scan by SecOps team, the same vulnerable files that were previously flagged have reemerged within the system. The vulnerability is rated as critical:&lt;/P&gt;
&lt;P&gt;CVE-2020-9493 – Apache Log4j v1.2.17.0&lt;BR /&gt;Reference: NVD - CVE-2020-9493&lt;/P&gt;
&lt;P&gt;The affected files have been identified in the following locations:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;lt;Studio_Home&amp;gt;/addons/scripts/lucene_migration_tool/lib/lucene-4-8.0.0.jar&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;Studio_Home&amp;gt;/addons/scripts/lucene_migration_tool/lib/lucene-8-8.0.0.jar&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Cause&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;This issue arises solely when Talend Studio is installed via the Talend Installer, resulting in the creation of the 'lucene_migration_tool' folder, which contains lucene-4-8.0.0.jar and lucene-8-8.0.0.jar. These Jar files utilize Apache Log4j version 1.2.17.0.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Please manually delete the 'lucene_migration_tool' folder from the directory located at '&amp;lt;Studio_Home&amp;gt;/addons/scripts/'. This migration tool is only useful when creating an index from a version lower than Talend Studio 7.2. For further details, please read this documentation &lt;A href="https://help.qlik.com/talend/en-US/release-notes/8.0/data-quality-migration" target="_self"&gt;page&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Kindly know that the&amp;nbsp;'lucene_migration_tool' folder will not be created in the new version of Talend Installer.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Internal Investigation ID(s)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;SUPPORT-3978&lt;/P&gt;
&lt;P&gt;TINSTL-238&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Talend Studio&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 20 Jun 2025 01:04:44 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Talend-Data-Integration-CVE-2020-9493-Apache-Log4j-v1-2-17/ta-p/2520960</guid>
      <dc:creator>FangZhen_TAO</dc:creator>
      <dc:date>2025-06-20T01:04:44Z</dc:date>
    </item>
  </channel>
</rss>

