Hi all,
During a scan of our infra, our system detected that in splunk version 8.1.7.1 , there is still present log4j library vulnerable to CVE-2021-44228. prior to the upgrade to this version we deleted the compromised files following the workaround in the Splunk Blog about this topic.
As this version has that vulnerability patched, I´d like to know how the process works, as there are log4j files in the affected version present. Thanks in advance for your help.
Best regards.
There have created 8.7.1.2 where those should be fixed. Also 8.1.8 is already out, I suppose that also this should contain those fixes.