Jump to content

Reload4j

From Wikipedia, the free encyclopedia
This is an old revision of this page, as edited by Man thinking (talk | contribs) at 19:06, 14 January 2022. The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Reload4j [1] was created by the original author of log4j 1.x, Ceki Gulcu. Reload4j is a fork of log4j version 1.2.17. It preserves the same java name space, that is "org.apache.log4j". However, is is published under the "ch.qos.reload4j" group id in Maven Central.

The aim of the reload4j project is to provide a migration path to those users wishing to correct log4j 1.x security issues. For many companies this is a requirement by the FTC[2]. Upgrading to a newer version of log4j 1.x is not possible since the project has been declared EOL [3] by the Apache Software Foundation. This decision was reaffirmed in 2022[4]. Moreover, log4j 2.x has a considerably different API and configuration style.

Corrected common vulnerabilities and exposures (CVE)

Reload4j fixes the following vulnerabilities:

  • CVE-2021-4104[5]
  • CVE-2019-17571[6]
First release

Version 1.2.8.0 of reload4j was released on January the 12th, 2022 and is available for public consumption.

slf4j-reload4j module

Subsequently, the SLF4J project has released SLF4J version 1.7.33[7] with support for reload4j via the slf4j-reload4j module.[8]

References

  1. ^ "reload4j". reload4j.qos.ch. Retrieved 2022-01-14.
  2. ^ "FTC warns companies to remediate Log4j security vulnerability". Federal Trade Commission. 2022-01-04. Retrieved 2022-01-14.
  3. ^ "Apache™ Logging Services™ Project Announces Log4j™ 1 End-Of-Life; Recommends Upgrade to Log4j 2". Apache Logging Services.
  4. ^ Ron, Grabowski (2022-01-06). "Log4j 1 End-of-Life Statement". lists.apache.org. Apache Logging Services.{{cite web}}: CS1 maint: url-status (link)
  5. ^ CVE.report; CVE. "CVE-2021-4104". CVE.report. Retrieved 2022-01-14.
  6. ^ CVE.report; CVE. "CVE-2019-17571". CVE.report. Retrieved 2022-01-14.
  7. ^ SLF4J.ORG (2022-01-13). "Release of version 1.7.33". SLF4J. SLF4J.ORG.{{cite web}}: CS1 maint: numeric names: authors list (link)
  8. ^ "Reload4jLoggerAdapter (SLF4J 2.0.0-alpha6 API)". www.slf4j.org. Retrieved 2022-01-14.