<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log4j Vulnerability in Installing and Upgrading</title>
    <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j-Vulnerability/m-p/2408821#M12031</link>
    <description>&lt;P&gt;We are using Talend studio 7.3.1.20202019_1130 and build the jobs and schedule them in Unix server. &lt;/P&gt;&lt;P&gt;The Build provides us log4j..2.12 versions. &lt;/P&gt;&lt;P&gt;We implemented two steps as talend advised to overcome log4j Vulnerability as given below&lt;/P&gt;&lt;P&gt; 1)  In log4j2 xml file included {nolookups} &lt;/P&gt;&lt;P&gt; 2) In Studio under Run/debug JVM arguments added -Dlog4j2.formatMsgNoLookups=true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But our organization recommends following Apache standards "&lt;/P&gt;&lt;P&gt;customers to upgrade to Log4j 2.3.1 (for Java 6), 2.12.3 (for Java 7), or 2.17.0 (for Java 8 and later)"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So please advise how can we go for next steps, do we need to upgrade or any patch available so on, what is the best solution&lt;/P&gt;</description>
    <pubDate>Fri, 15 Nov 2024 22:52:05 GMT</pubDate>
    <dc:creator>sgovinda1654106847</dc:creator>
    <dc:date>2024-11-15T22:52:05Z</dc:date>
    <item>
      <title>Log4j Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j-Vulnerability/m-p/2408821#M12031</link>
      <description>&lt;P&gt;We are using Talend studio 7.3.1.20202019_1130 and build the jobs and schedule them in Unix server. &lt;/P&gt;&lt;P&gt;The Build provides us log4j..2.12 versions. &lt;/P&gt;&lt;P&gt;We implemented two steps as talend advised to overcome log4j Vulnerability as given below&lt;/P&gt;&lt;P&gt; 1)  In log4j2 xml file included {nolookups} &lt;/P&gt;&lt;P&gt; 2) In Studio under Run/debug JVM arguments added -Dlog4j2.formatMsgNoLookups=true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But our organization recommends following Apache standards "&lt;/P&gt;&lt;P&gt;customers to upgrade to Log4j 2.3.1 (for Java 6), 2.12.3 (for Java 7), or 2.17.0 (for Java 8 and later)"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So please advise how can we go for next steps, do we need to upgrade or any patch available so on, what is the best solution&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 22:52:05 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j-Vulnerability/m-p/2408821#M12031</guid>
      <dc:creator>sgovinda1654106847</dc:creator>
      <dc:date>2024-11-15T22:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j-Vulnerability/m-p/2408822#M12032</link>
      <description>&lt;P&gt;@sri ranga pavan govinda​, please read this &lt;A href="https://help.talend.com/r/EeTpT8r7xmeq1HtTGQBqGA/zX7iWLX6GgxOAjJPlpXNYA" alt="https://help.talend.com/r/EeTpT8r7xmeq1HtTGQBqGA/zX7iWLX6GgxOAjJPlpXNYA" target="_blank"&gt;page &lt;/A&gt;about log4j issue, if you are using enterprise subscription products, raise a ticket on Talend Support Portal to request a patch. &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Shong&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 07:58:46 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j-Vulnerability/m-p/2408822#M12032</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2022-06-02T07:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j Vulnerability</title>
      <link>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j-Vulnerability/m-p/2408823#M12033</link>
      <description>&lt;P&gt;Hello guys I was also having trouble doing the update version of the log4j library. Looking on the internet I found this article that was accurate in solving the problem. I hope they help people who use the open version.&lt;/P&gt;&lt;P&gt;&lt;A href="https://rob-ex.com/manual/7.0/en/topic/updating-talend-log4j-libraries" alt="https://rob-ex.com/manual/7.0/en/topic/updating-talend-log4j-libraries" target="_blank"&gt;Updating Talend Log4j libraries - User's Manual - 7.0 (rob-ex.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 12:14:54 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Installing-and-Upgrading/Log4j-Vulnerability/m-p/2408823#M12033</guid>
      <dc:creator>Evandao</dc:creator>
      <dc:date>2022-08-19T12:14:54Z</dc:date>
    </item>
  </channel>
</rss>

