| //// |
| // Licensed to the Apache Software Foundation (ASF) under one or more |
| // contributor license agreements. See the NOTICE file distributed with |
| // this work for additional information regarding copyright ownership. |
| // The ASF licenses this file to You under the Apache License, Version 2.0 |
| // (the "License"); you may not use this file except in compliance with |
| // the License. You may obtain a copy of the License at |
| // |
| // https://www.apache.org/licenses/LICENSE-2.0 |
| // |
| // Unless required by applicable law or agreed to in writing, software |
| // distributed under the License is distributed on an "AS IS" BASIS, |
| // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| // See the License for the specific language governing permissions and |
| // limitations under the License. |
| //// |
| |
| :cve-url-prefix: https://nvd.nist.gov/vuln/detail |
| |
| = Security |
| |
| The Logging Services Security Team takes security seriously. |
| This allows our users to place their trust in Log4j for protecting their mission-critical data. |
| In this page we will help you find guidance on security-related issues and access to known vulnerabilities. |
| |
| include::_log4j1-eol.adoc[] |
| |
| [#support] |
| == Getting support |
| |
| If you need help on building or configuring Logging Services projects or other help on following the instructions to mitigate the known vulnerabilities listed here, please use our xref:support.adoc#discussions[user support channels]. |
| |
| [TIP] |
| ==== |
| If you need to apply a source code patch, use the building instructions for the project version that you are using. |
| These instructions can be found in `BUILDING.adoc`, `BUILDING.md`, etc. files distributed with the sources. |
| ==== |
| |
| [#reporting] |
| == Reporting vulnerabilities |
| |
| If you have encountered an unlisted security vulnerability or other unexpected behaviour that has a security impact, or if the descriptions here are incomplete, please report them **privately** to mailto:security@logging.apache.org[the Logging Services Security Team]. |
| |
| [IMPORTANT] |
| ==== |
| We urge you to **carefully read the threat model** detailed in following sections before submitting a report. |
| It guides users on certain safety instructions while using Logging Services software and elaborates on what counts as an unexpected behaviour that has a security impact. |
| ==== |
| |
| include::_threat-model-common.adoc[] |
| |
| include::_threat-model-log4j.adoc[] |
| |
| include::_threat-model-log4net.adoc[] |
| |
| [#policy] |
| == Vulnerability handling policy |
| |
| The Logging Services Security Team follows the https://www.apache.org/security/committers.html[ASF Project Security] guide for handling security vulnerabilities. |
| |
| Reported security vulnerabilities are subject to voting (by means of https://logging.apache.org/guidelines.html[_lazy approval_], preferably) in the private mailto:security@logging.apache.org[security mailing list] before creating a CVE and populating its associated content. |
| This procedure involves only the creation of CVEs and blocks neither (vulnerability) fixes, nor releases. |
| |
| [#vdr] |
| == Vulnerability Disclosure Report (VDR) |
| |
| include::_sbom.adoc[] |
| |
| [#vulnerabilities] |
| == Known vulnerabilities |
| |
| include::_vulnerabilities.adoc[] |