Log4j vulnerability in jetty and CFBuilder
Hi,
I read the posts about log4j but it seems like there is still an unresolved vulnerability in the jetty\lib\ext\log4j-1.2.17.jar file? Was this ever resolved?
Also, our scanners are flagging log4j under CFBuilder, I haven't seen any mitigation steps for that, did I miss something? These are reported (from the root ColdFusion Builder directory):
plugins\com.adobe.ide.coldfusion.dictionary_3.2.1.201902041055\lib\log4j-1.2.9.jar
\configuration\org.eclipse.osgi\31\0\.cp\lib\log4j-1.2.9.jar
Thanks for any information,
Alicia
