[JBoss JIRA] (JBIDE-27078) The "thread-racing" quickstart (imported from RH central) is missing an important note in the documentation
by Zbyněk Červinka (Jira)
Zbyněk Červinka created JBIDE-27078:
---------------------------------------
Summary: The "thread-racing" quickstart (imported from RH central) is missing an important note in the documentation
Key: JBIDE-27078
URL: https://issues.redhat.com/browse/JBIDE-27078
Project: Tools (JBoss Tools)
Issue Type: Bug
Components: central
Reporter: Zbyněk Červinka
Assignee: Jeff MAURY
The *thread-racing* quickstart is missing important note in the README.md and README.html files. Open one of the files and search for the *Run the Quickstart in Red Hat JBoss Developer Studio or Eclipse* section. There should be the following note (like in other quickstarts such as jta-crash-rec or messaging-clustering):
*{color:#FF8B00}NOTE:Within JBoss Developer Studio, be sure to define a server runtime environment that uses the standalone-full.xml configuration file.{color}*
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
5 years, 7 months
[JBoss JIRA] (JBIDE-27078) The "thread-racing" quickstart (imported from RH central, version 7.0.0.GA) is missing an important note in the documentation
by Zbyněk Červinka (Jira)
[ https://issues.redhat.com/browse/JBIDE-27078?page=com.atlassian.jira.plug... ]
Zbyněk Červinka updated JBIDE-27078:
------------------------------------
Summary: The "thread-racing" quickstart (imported from RH central, version 7.0.0.GA) is missing an important note in the documentation (was: The "thread-racing" quickstart (imported from RH central) is missing an important note in the documentation)
> The "thread-racing" quickstart (imported from RH central, version 7.0.0.GA) is missing an important note in the documentation
> -----------------------------------------------------------------------------------------------------------------------------
>
> Key: JBIDE-27078
> URL: https://issues.redhat.com/browse/JBIDE-27078
> Project: Tools (JBoss Tools)
> Issue Type: Bug
> Components: central
> Reporter: Zbyněk Červinka
> Assignee: Jeff MAURY
> Priority: Minor
>
> The *thread-racing* quickstart is missing important note in the README.md and README.html files. Open one of the files and search for the *Run the Quickstart in Red Hat JBoss Developer Studio or Eclipse* section. There should be the following note (like in other quickstarts such as jta-crash-rec or messaging-clustering):
> *{color:#FF8B00}NOTE:Within JBoss Developer Studio, be sure to define a server runtime environment that uses the standalone-full.xml configuration file.{color}*
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
5 years, 7 months
[JBoss JIRA] (JBIDE-27040) Update log4j to 2.13.0(due to CVE-2019-17571)
by Josef Kopriva (Jira)
[ https://issues.redhat.com/browse/JBIDE-27040?page=com.atlassian.jira.plug... ]
Josef Kopriva closed JBIDE-27040.
---------------------------------
Closing, PR is merged.
> Update log4j to 2.13.0(due to CVE-2019-17571)
> ----------------------------------------------
>
> Key: JBIDE-27040
> URL: https://issues.redhat.com/browse/JBIDE-27040
> Project: Tools (JBoss Tools)
> Issue Type: Bug
> Components: build, openshift
> Affects Versions: 4.14.0.Final
> Reporter: Josef Kopriva
> Assignee: Josef Kopriva
> Priority: Major
> Fix For: 4.14.0.Final
>
>
> From repo:
> {code:java}
> CVE-2019-17571
> moderate severity
> Vulnerable versions: >= 1.2, <= 1.2.27
> Patched version: No fix
> Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
> {code}
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
5 years, 7 months