# Log4j vulnerability

**URL:** <https://community.openhab.org/t/log4j-vulnerability/129863>\
**Category:** Development\
**Created:** [December 10, 2021, 3:04pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863 "2021-12-10T15:04:31Z")\
**Posts on this page:** 1\
**Showing post:** 73

<div class="post-metadata">

**Author:** ![splatch](https://community.openhab.org/user_avatar/community.openhab.org/splatch/32/33925_2.png) [@splatch](https://community.openhab.org/u/splatch)\
**Post date:** [December 16, 2021, 5:08pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/73 "2021-12-16T17:08:16Z")

</div>

If you ask me, the proper fix for this vulnerability does not require openhab to wait for Karaf release. Solution is here: [Override pax logging version to address #1349. by splatch · Pull Request #1350 · openhab/openhab-distro · GitHub](https://github.com/openhab/openhab-distro/pull/1350). It forces use of newest release of pax logging which contains fixed version of log4j.

Note old version of pax is still installed in filesystem, it can be removed later on as its early banishment causes build to fail.

---

_[View the full topic](https://community.openhab.org/t/log4j-vulnerability/129863)._
