Vulnerable version of Log4j detected #6009
Closed
brownmic117
started this conversation in
General
Replies: 1 comment 7 replies
-
It seems to be a dependency of SUMO, which is the traffic simulator used by Webots. |
Beta Was this translation helpful? Give feedback.
7 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hail!
When deploying Webots to our labs, our security solution lit up with warnings that Webots [R2023a] is running a vulnerable version of Log4j (lisum-gui.jar)
As we're now caught in the rough position of cybersecurity wanting us to get shot of Webots due to the vulnerability, and the academic teams stating that there is nothing other than Webots will do the job -- I don't suppose there is any way for us to patch Webots to mitigate this vulnerability? (I could delete 'lisum-gui.jar' on each installation... but I have yet to learn what it does, thus, what or how much it will break.)
Beta Was this translation helpful? Give feedback.
All reactions