Coldfusion API Manager analytics service requires log4j-1.2.17.jar
Is there any chance this will be updated in the future? I am getting a lot of heat from the security people because the scans keep coming back with log4j vulns.
The analytics service is using an old version of elasticsearch that requires log4j-1.2.17.jar
Does anyone know of anyway to not usre the analytics service and still run the API manager or know of any work arounds to use a new elastic search? I know we can remove the jndi classes and put some flags on the JVM but the security folks see the file and thats all they care about.
This is the case for both coldfusion 2021 api manager and coldfusion 2023 api manager
Example directory
C:\ColdFusion2023APIManager\database\analytics\lib
