PostgreSQL JDBC and the log4j CVE - Mailing list pgsql-jdbc

From Dave Cramer
Subject PostgreSQL JDBC and the log4j CVE
Date
Msg-id CADK3HHJ1RPU1wWxqY7Y0uxc_6-87Bh7a5NoLPw=__VTbptjoeA@mail.gmail.com
Whole thread Raw
List pgsql-jdbc

Dave Cramer


---------- Forwarded message ---------
From: JDBC Project via PostgreSQL Announce <announce-noreply@postgresql.org>
Date: Mon, 13 Dec 2021 at 10:47
Subject: PostgreSQL JDBC and the log4j CVE
To: PostgreSQL Announce <pgsql-announce@lists.postgresql.org>


 

PostgreSQL JDBC and the log4j CVE

A CVE has been reported on the popular logging implementation log4j.

As the PostgreSQL JDBC driver does not include this as a dependency we have determined that there is no need for concern. The driver is not vulnerable to this CVE.

Regards,

Dave Cramer

pgjdbc team

This email was sent to you from JDBC Project. It was delivered on their behalf by the PostgreSQL project. Any questions about the content of the message should be sent to JDBC Project.

You were sent this email as a subscriber of the pgsql-announce mailinglist, for for one of the content tags Related Open Source or Security. To unsubscribe from further emails, or change which emails you want to receive, please click the personal unsubscribe link that you can find in the headers of this email, or visit https://lists.postgresql.org/unsubscribe/.
 

pgsql-jdbc by date:

Previous
From: Dave Cramer
Date:
Subject: Re: [QUESTION] How to retrieve type info for ROW
Next
From: Dave Cramer
Date:
Subject: [pgjdbc/pgjdbc] d0392b: fix: return getIndexInfo metadata columns in UPPER...