<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remove default log4j version and add a new version globally in Talend Studio</title>
    <link>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288926#M62345</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;can you help me please, it's very important and time critical for our Company. &lt;/P&gt;&lt;P&gt;We need a TOS with log4j 2.x Version whatever DI or BD.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Torsten&lt;/P&gt;&lt;P&gt;mailto:torsten.t.schroeder@deutschebahn.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Apr 2022 07:07:55 GMT</pubDate>
    <dc:creator>toshi1</dc:creator>
    <dc:date>2022-04-01T07:07:55Z</dc:date>
    <item>
      <title>Remove default log4j version and add a new version globally</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288918#M62337</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;Currently talend uses log4j 2.12 version which has the latest vulnerability discovered. As I can see for each job there is a separate POM file and all those files are using that log4j version. Do I need to manually go to each and every POM file and change it or is there a easy way to change this version to new log4j 2.17.1 version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://www.secureworks.com/blog/log4j-vulnerability-faqs# :~:text=rated%20moderate%20severity.-,Version%202.17.,was%20disclosed%20on%20December%2016.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 10:27:22 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288918#M62337</guid>
      <dc:creator>heshkaru</dc:creator>
      <dc:date>2022-03-01T10:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Remove default log4j version and add a new version globally</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288919#M62338</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Could you please indicate which talend solution are you using? &lt;/P&gt;&lt;P&gt;Here is online documentation about: &lt;A href="https://help.talend.com/r/EeTpT8r7xmeq1HtTGQBqGA/zX7iWLX6GgxOAjJPlpXNYA" alt="https://help.talend.com/r/EeTpT8r7xmeq1HtTGQBqGA/zX7iWLX6GgxOAjJPlpXNYA" target="_blank"&gt;TalendHelpCenter: Official statement and remediation efforts for Log4j2 security issue (CVE-2021-44228)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Sabrina&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 04:29:43 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288919#M62338</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2022-03-02T04:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Remove default log4j version and add a new version globally</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288920#M62339</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Im using talend openstudio 7.4.1.&lt;/P&gt;&lt;P&gt;This is regarding the latest vulnerabilitiy discovered in dec 2021.&lt;/P&gt;&lt;P&gt;CVE-2021-44228 and CVE-2021-45046&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I build the job it automatically takes log4j 2.12.1 version. So I need to manually add 2.17.1 after building the job.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to change the default log4j version to new version rather than adding 'nolookups' &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 05:37:10 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288920#M62339</guid>
      <dc:creator>heshkaru</dc:creator>
      <dc:date>2022-03-02T05:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Remove default log4j version and add a new version globally</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288921#M62340</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Note: The mitigation steps that we have described in the Talend Help apply to TOS as well.&lt;/P&gt;&lt;P&gt;For your use case, you could install the module externally from maven repository.&lt;/P&gt;&lt;P&gt;1.Download the jar from &lt;A href="https://mvnrepository.com/artifact/org.apache.logging.log4j" alt="https://mvnrepository.com/artifact/org.apache.logging.log4j" target="_blank"&gt;https://mvnrepository.com/artifact/org.apache.logging.log4j&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2.select the appropriate jar which needs to be upgraded&lt;/P&gt;&lt;P&gt;3.select the module in TOS &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="0695b00000LxbytAAB.png"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/129665i0C9E74B3EC68902C/image-size/large?v=v2&amp;amp;px=999" role="button" title="0695b00000LxbytAAB.png" alt="0695b00000LxbytAAB.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="0695b00000LxbNFAAZ.png"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/127776i0899B5847AF6B3F9/image-size/large?v=v2&amp;amp;px=999" role="button" title="0695b00000LxbNFAAZ.png" alt="0695b00000LxbNFAAZ.png" /&gt;&lt;/span&gt;4.Click Detect and install module&lt;/P&gt;&lt;P&gt;Let us know if you can see the latest jar exist  when you build the job.&lt;/P&gt;&lt;P&gt;Hope this will help.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Sabrina&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 05:53:08 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288921#M62340</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2022-03-02T05:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Remove default log4j version and add a new version globally</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288922#M62341</link>
      <description>&lt;P&gt;How do i access this screen.&lt;/P&gt;&lt;P&gt;I think this way is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 06:25:38 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288922#M62341</guid>
      <dc:creator>heshkaru</dc:creator>
      <dc:date>2022-03-02T06:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Remove default log4j version and add a new version globally</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288923#M62342</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Let us know if these screenshots are broken from your side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="0695b00000ODVQWAA5.png"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/137314iCC51AC19304971DB/image-size/large?v=v2&amp;amp;px=999" role="button" title="0695b00000ODVQWAA5.png" alt="0695b00000ODVQWAA5.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="0695b00000ODVQMAA5.png"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/143786i16FD55AE48D76798/image-size/large?v=v2&amp;amp;px=999" role="button" title="0695b00000ODVQMAA5.png" alt="0695b00000ODVQMAA5.png" /&gt;&lt;/span&gt;Best regards&lt;/P&gt;&lt;P&gt;Sabrina&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 07:08:13 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288923#M62342</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2022-03-02T07:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: Remove default log4j version and add a new version globally</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288924#M62343</link>
      <description>&lt;P&gt;Fixed it.&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 08:52:03 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288924#M62343</guid>
      <dc:creator>heshkaru</dc:creator>
      <dc:date>2022-03-02T08:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Remove default log4j version and add a new version globally</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288925#M62344</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Great it works. Feel free to let us know if there is any further help we can give.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Sabrina&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 01:55:18 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288925#M62344</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2022-03-03T01:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Remove default log4j version and add a new version globally</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288926#M62345</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;can you help me please, it's very important and time critical for our Company. &lt;/P&gt;&lt;P&gt;We need a TOS with log4j 2.x Version whatever DI or BD.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Torsten&lt;/P&gt;&lt;P&gt;mailto:torsten.t.schroeder@deutschebahn.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 07:07:55 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288926#M62345</guid>
      <dc:creator>toshi1</dc:creator>
      <dc:date>2022-04-01T07:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: Remove default log4j version and add a new version globally</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288927#M62346</link>
      <description>&lt;P&gt;@Torsten Schröder​&amp;nbsp;Hi, &lt;/P&gt;&lt;P&gt;This is the documentation I did for the Log4j Fix&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Latest vulnerability related to Log4j is found in below.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.secureworks.com/blog/log4j-vulnerability-faqs#:~:text=rated%20moderate%20severity.-,Version%202.17.,was%20disclosed%20on%20December%2016." alt="https://www.secureworks.com/blog/log4j-vulnerability-faqs#:~:text=rated%20moderate%20severity.-,Version%202.17.,was%20disclosed%20on%20December%2016." target="_blank"&gt;https://www.secureworks.com/blog/log4j-vulnerability-faqs#:~:text=rated%20moderate%20severity.-,Version%202.17.,was%20disclosed%20on%20December%2016.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;RCA: After Talend Zip file is deployed to server, vulnerabilites are scanned from Talend Libraries.&lt;/P&gt;&lt;P&gt;Fix Number 1 : Remove dependencies from Talend Studio itself (Best Option)&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Open Talend Studio&lt;/LI&gt;&lt;LI&gt;Navigate to Window → Show View → Other → Modules and click open.&lt;/LI&gt;&lt;LI&gt;Module window will be displayed and type “log4j“ in the search bar.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4. Select the necessary dependency and click on the Maven URI.&lt;/P&gt;&lt;P&gt;5. A popup will be open&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For windows users all the inbuild dependencies are stored in “C:\Program Files (x86)\TOS_DI-7.4.1\studio\plugins\org.talend.libraries.apache_7.4.1.20201127_0205\lib” folder. Navigate to that folder and delete the old jar version and paste the new jar version.&lt;/P&gt;&lt;P&gt;6. Click … and add the new jar file.&lt;/P&gt;&lt;P&gt;7. Navigate to the folder mention in red color above and select the new jar version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;8. Click “Detect the module install status“ and Click OK.&lt;/P&gt;&lt;P&gt;9. This way you can easily change/update dependencies provided by talend.&lt;/P&gt;&lt;P&gt;10. Once you build the job and extract it and navigate to 'libs' folder you can see that newly updated versions are reflected to the libraries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 07:42:51 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288927#M62346</guid>
      <dc:creator>heshkaru</dc:creator>
      <dc:date>2022-04-01T07:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: Remove default log4j version and add a new version globally</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288928#M62347</link>
      <description>&lt;P&gt;Hello, -&amp;gt; all is fixed &lt;/P&gt;&lt;P&gt;1st, Thanks for the nice and quick reply from @Heshan Karunaratne​ - It saved me, and helped a lot.&lt;/P&gt;&lt;P&gt;2nd. For those out there who also struggle with the security themes of log4j 1.x and 2.x hereafter my crucial points that have brought success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) I'd to understand the substitution from - to with the bridging libs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;s.a. &lt;A href="https://stackoverflow.com/questions/43154005/slf4j-log4j-bridge-with-log4j-2-8-1" alt="https://stackoverflow.com/questions/43154005/slf4j-log4j-bridge-with-log4j-2-8-1" target="_blank"&gt;slf4j-log4j bridge with log4j 2.8.1&lt;/A&gt; siehe Antwort&lt;UL&gt;&lt;LI&gt;slf4j-log4j12 Bridge -&amp;gt; altes Binding -&amp;gt; neues: log4j-slf4j-impl&lt;UL&gt;&lt;LI&gt;log4j-api (2.8.1)&lt;/LI&gt;&lt;LI&gt;log4j-core (2.8.1)&lt;/LI&gt;&lt;LI&gt;log4j-slf4j-impl (2.8.1)&lt;/LI&gt;&lt;LI&gt;slf4j-api (1.7.25)&lt;/LI&gt;&lt;LI&gt;zusätzlich Bridge to log4j&lt;UL&gt;&lt;LI&gt;log4j-1.2-api (2.8.1)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Benötigte Bibliotheken von SLF4J und Log4j 2.x -&amp;gt; in &lt;A href="https://mvnrepository.com/search?q=log4j" alt="https://mvnrepository.com/search?q=log4j" target="_blank"&gt;MVN log4j&lt;/A&gt; aktuelle Versionsstände ermitteln&lt;UL&gt;&lt;LI&gt;2.17.2&lt;UL&gt;&lt;LI&gt;log4j-core&lt;/LI&gt;&lt;LI&gt;log4j-api&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-slf4j-impl/2.17.2" alt="https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-slf4j-impl/2.17.2" target="_blank"&gt;log4j-slf4j-impl&lt;/A&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://logging.apache.org/log4j/2.x/log4j-slf4j-impl/" alt="https://logging.apache.org/log4j/2.x/log4j-slf4j-impl/" target="_blank"&gt;Log4j 2 SLF4J Binding&lt;/A&gt;&lt;UL&gt;&lt;LI&gt;log4j-slf4j-impl should be used with SLF4J 1.7.x releases or older.&lt;/LI&gt;&lt;LI&gt;log4j-slf4j18-impl should be used with SLF4J 1.8.x releases or newer.&lt;/LI&gt;&lt;LI&gt;NOTE not to take simultanously log4j-to-slf4j-2.0.jar&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;log4j-1.2-api&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;1.7.36&lt;UL&gt;&lt;LI&gt;slf4j-api&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) I'd to learn, that with my old TOS BD 7.2.1 success is to difficult to achieve&lt;/P&gt;&lt;P&gt;I'm exported the TOS BD 7.2.1 items and import them to TOS DI 8.0.1, that helped me a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wish to Thanks all of you, you're a great community&lt;/P&gt;&lt;P&gt;Torsten&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 15:36:09 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288928#M62347</guid>
      <dc:creator>toshi1</dc:creator>
      <dc:date>2022-04-06T15:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: Remove default log4j version and add a new version globally</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288929#M62348</link>
      <description>&lt;P&gt;My pleasure&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 16:25:33 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Remove-default-log4j-version-and-add-a-new-version-globally/m-p/2288929#M62348</guid>
      <dc:creator>heshkaru</dc:creator>
      <dc:date>2022-04-06T16:25:33Z</dc:date>
    </item>
  </channel>
</rss>

