gpt4 book ai didi

java - Apache Log4j 安全漏洞 - 2.17.0 jar 无法将查找值加载到 log4j2.xml 中

转载 作者:行者123 更新时间:2023-12-05 04:39:22 25 4
gpt4 key购买 nike

根据 Apache Log4j Security Vulnerabilities guideline我已经在我的应用程序中更新了 2.17.0 jar。

未生成升级后日志文件。

Spring version : 5.3.13
Log4j version : 2.17.0
java : 1.8

引用下面给出的log4j2.xml

<?xml version="1.0" encoding="UTF-8"?>
<Configuration monitorInterval="1">
<Properties>

<Property name="log-path">${appconfig:log_path}</Property>
<Property name="log-name">${appconfig:filename}</Property>
<Property name="archive-days">${appconfig:archive_days}</Property>
<Property name="file-level">${appconfig:file_level}</Property>
<Property name="console-level">${appconfig:console_level}</Property>


</Properties>
<Appenders>

<Routing name="route-log">
<Routes pattern="${ctx:routingLogFile}">

<Route>
<RollingFile name="default-log" fileName="${log-path}/${log-name}.log"
filePattern="${log-path}/${date:yyyy-MM}/${log-name}.%d{MM-dd-yyyy}-%i.log.gz" append="true">
<PatternLayout
pattern="%d{MM/dd/yyyy HH:mm:ss.SSS z} %X{machine-name} %X{app-name} [%t] %-5level %logger{36}:%-3L - %msg%n" />
<Policies>
<TimeBasedTriggeringPolicy />
<SizeBasedTriggeringPolicy size="150 MB"/>
</Policies>
<DefaultRolloverStrategy max="1000">
<Delete basePath="${log-path}/" maxDepth="2">
<IfFileName glob="/${log-name}*.log.gz" />
<IfLastModified age="${archive-days}" />
</Delete>
</DefaultRolloverStrategy>
</RollingFile >
</Route>

</Routes>

</Routing>
<Console name="STDOUT" target="SYSTEM_OUT">
<PatternLayout pattern="%d{ISO8601} %-5level %30.30logger{1.}:%-3L - %m%n%throwable" />
</Console>
</Appenders>

<Loggers>
<Logger name="org.springframework" level="ERROR"/>
<Logger name="org.apache" level="ERROR"/>
<Root level="${file-level}" additivity="false">
<AppenderRef ref="route-log" />
<AppenderRef ref="STDOUT" />
</Root>
</Loggers>

</Configuration>

我正在使用下面给出的查找,以便从表中获取日志文件名、日志文件路径、日志级别、归档天数。

import org.apache.logging.log4j.core.LogEvent;
import org.apache.logging.log4j.core.config.plugins.Plugin;
import org.apache.logging.log4j.core.lookup.AbstractLookup;
import org.apache.logging.log4j.core.lookup.StrLookup;
import org.appconfig.properties.ApplicationProperties;
import org.springframework.util.StringUtils;

@Plugin(name = "appconfig", category = StrLookup.CATEGORY)
public class AppLog4JConfigDatabaseLookup extends AbstractLookup {

public String lookup(final LogEvent event, final String key) {


if (key.equalsIgnoreCase("filename")) {
return ApplicationProperties.getLogFilename();
}
if (key.equalsIgnoreCase("log_path")) {
return ApplicationProperties.getLogPath();
}
if (key.equalsIgnoreCase("file_level")) {
return ApplicationProperties.getFileLogLevel();
}
if (key.equalsIgnoreCase("console_level")) {
return ApplicationProperties.getConsoleLogLevel();
}
if (key.equalsIgnoreCase("app_name")) {
return ApplicationProperties.getAppName();
}
if (key.equalsIgnoreCase("archive_days")) {
return ApplicationProperties.getLogArchiveDays();
}

return key;
}
}

引用下面给出的服务类。

public class LoaderJob extends SchedulerAdapterJob {
@Autowired
private FileLoaderJob fileLoaderJob;

private static final Logger LOGGER = LogManager.getLogger(LoaderJob.class);
@Override
public void executeJob(JobExecutionContext jobExecutionContext) {
ThreadContext.put("routingLogFile","LOADER_LOGS");
try {
fileLoaderJob.execute();

}
catch (Exception e) {
LOGGER.error("Exception in "+getJobName()+" : "+ e.getMessage());
throw e;
}
finally {
ThreadContext.remove("routingLogFile");
}

}

}

它在 2.16.0 中工作正常,在 2.17.0 中不工作。任何解决方案将不胜感激。

最佳答案

根据 Apache 指南,您应该在路由模式中添加两个 $。但是在你的 log4j2.xml 中只包含一个

引用以下链接:https://logging.apache.org/log4j/log4j-2.2/faq.html

关于java - Apache Log4j 安全漏洞 - 2.17.0 jar 无法将查找值加载到 log4j2.xml 中,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/70457446/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com