From 9ee60949d3ceca3ab1fcf47c9214f7bf6baf89c6 Mon Sep 17 00:00:00 2001 From: amohamad Date: Fri, 26 Jun 2020 12:40:11 -0400 Subject: Upgrade Vulnerable Direct Dependencies [log4j] Signed-off-by: amohamad Issue-ID: SDC-3051 Upgrade from the vulnerable log4j 1.x to log4j 2.13.1 Add a log4j version property in sdc-main pom.xml Add two maven dependencies to respective child pom.xml Change name of log4j .properties and .xml config files to reflect log4j2 naming Update the configuration files to the totally new log4j 2 config syntax Replace PropertyConfigurator with LoggerContext Remove the abandoned log4j.lf5.util.ResourceUtils Signed-off-by: amohamad Change-Id: Ie0f141eb2e0337ee5b63b61dc1395ccd8040558d --- catalog-dao/src/test/resources/log4j.properties | 8 -------- catalog-dao/src/test/resources/log4j2.properties | 13 +++++++++++++ 2 files changed, 13 insertions(+), 8 deletions(-) delete mode 100644 catalog-dao/src/test/resources/log4j.properties create mode 100644 catalog-dao/src/test/resources/log4j2.properties (limited to 'catalog-dao/src/test') diff --git a/catalog-dao/src/test/resources/log4j.properties b/catalog-dao/src/test/resources/log4j.properties deleted file mode 100644 index c18c3daa0e..0000000000 --- a/catalog-dao/src/test/resources/log4j.properties +++ /dev/null @@ -1,8 +0,0 @@ -# Root logger option -log4j.rootLogger=info, stdout - -# Direct log messages to stdout -log4j.appender.stdout=org.apache.log4j.ConsoleAppender -log4j.appender.stdout.Target=System.out -log4j.appender.stdout.layout=org.apache.log4j.PatternLayout -log4j.appender.stdout.layout.ConversionPattern=%d{yyyy-MM-dd HH:mm:ss} %-5p %c{1}:%L - %m%n diff --git a/catalog-dao/src/test/resources/log4j2.properties b/catalog-dao/src/test/resources/log4j2.properties new file mode 100644 index 0000000000..f028cd07c8 --- /dev/null +++ b/catalog-dao/src/test/resources/log4j2.properties @@ -0,0 +1,13 @@ +status = error +dest = err +name = PropertiesConfig + +appender.console.type = Console +appender.console.name = STDOUT +appender.console.layout.type = PatternLayout +appender.console.layout.pattern = %d{yyyy-MM-dd HH:mm:ss} %-5p %c{1}:%L - %m%n +appender.console.filter.threshold.type = ThresholdFilter +appender.console.filter.threshold.level = info + +rootLogger.level = info +rootLogger.appenderRef.stdout.ref = STDOUT \ No newline at end of file -- cgit 1.2.3-korg