Given the log4j vulnerability and recommended configuration changes suggested here: SonarQube and the Log4J vulnerability
Can someone from SonarCloud confirm that these changes have been applied?
Thanks,
Luke.
Given the log4j vulnerability and recommended configuration changes suggested here: SonarQube and the Log4J vulnerability
Can someone from SonarCloud confirm that these changes have been applied?
Thanks,
Luke.
Hey there.
Thanks for asking. Our investigation leads us to believe SonarCloud is not vulnerable in its current state.
In any case, we take such reports seriously and we will update log4j on Monday to be extra sure.
Hey @Max_Kroll
We have updated it – and it was deployed.
We’ll handle any further updates on this thread.
https://community.sonarsource.com/t/sonarqube-sonarcloud-and-the-log4j-vulnerability/54721/25
So I’ll close this one.