Results 1 to 10 of 16

Hybrid View

  1. #1
    Hi Giuseppe,
    Everything worked
    1)I've added log4j2.xml and i can see the adapters logs. Note in the lightstream servers packages, you guys are using log4j-api-2.17.0.jar and log4j-core-2.17.0.jar which are dangerous. You can google "log4j security vulnerability" to see which versions are safe
    2)I've renabled the adapters and in the xml file and everything is working fine.
    Thanks a lot for the quick responses!

  2. #2
    Administrator
    Join Date
    Feb 2012
    Location
    Milano
    Posts
    716
    Hi baalbaki,

    Thank you for the feedback.

    But please let me stress out that we are well aware of the Log4Shell vulnerability but in short Lightstreamer is not affected.

    The Lightstreamer Server has been using the logback library for its own logging since version 5.0. Logback is not affected by this vulnerability because it does not use the vulnerable log4j-core library.
    Indeed the Lightstreamer Server comes with a few preinstalled demos, whose adapters use log4j for logging. These are the demos that populate the welcome page in a fresh installation of Lightstreamer.
    But we don't expect that a public installation of Lightstreamer Server includes the demo Adapter Set and/or allows access to the demos. In the PRODUCTION_SECURITY_NOTES.TXT document that is included in the root folder of all Lightstreamer distributions, we have always recommended removing the preinstalled demos.
    We had already upgraded our Lightstreamer distribution to version 2.17.0 but we also know that another minor problem was found shortly after and fixed with the version 2.17.1. I confirm that the next release will contain the update.

    Obviously if you decide to use log4j2 in your adapters it is absolutely recommended to upgrade to the latest version (2.17.1).

    Regards,
    Giuseppe

 

 

Similar Threads

  1. LightStreamer Server Failing Upon A Connection
    By ErikLatimer in forum General
    Replies: 3
    Last Post: October 3rd, 2018, 12:06 PM
  2. Replies: 1
    Last Post: June 13th, 2016, 10:01 AM
  3. Replies: 5
    Last Post: January 18th, 2016, 10:10 AM
  4. Internal cause codes & Session callbacks
    By jonasby1 in forum General
    Replies: 4
    Last Post: February 16th, 2012, 08:47 AM
  5. Internal cause codes
    By BKnight in forum General
    Replies: 3
    Last Post: February 10th, 2012, 09:33 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
All times are GMT +1. The time now is 09:51 AM.