From: "salamani (Ravi Salamani)" Date: 2021-12-23T14:11:41+00:00 Subject: [ruby-core:106777] [Ruby master Bug#18424] Is Ruby is vulnerable to log4j? Issue #18424 has been updated by salamani (Ravi Salamani). mame (Yusuke Endoh) wrote in #note-1: > The Ruby package itself does not depend on log4j. For an application or library written in Ruby, please ask to its maintainer. https://github.com/ruby/ruby/blob/master/spec/bundler/resolver/platform_spec.rb#L31 Does it installs log4j? ---------------------------------------- Bug #18424: Is Ruby is vulnerable to log4j? https://bugs.ruby-lang.org/issues/18424#change-95479 * Author: salamani (Ravi Salamani) * Status: Rejected * Priority: Normal * ruby -v: master * Backport: 2.6: UNKNOWN, 2.7: UNKNOWN, 3.0: UNKNOWN ---------------------------------------- I observed that the ruby uses zookeeper, dep "slyphon-log4j", "= 1.2.15". Is Ruby is vulnerable to log4j? -- https://bugs.ruby-lang.org/ Unsubscribe: