monasca-agent/monasca_agent/collector
Jan Zerebecki dbb766218e Remove JMSAppender.class to avoid CVE-2021-4104,
CVE-2022-23302, CVE-2022-23305, and CVE-2022-23307.

Though it does not contain a vulnerable configuration of log4j, to avoid
needing to prove that and false positives of security scanners, this
commit is the result of running the following commands:

zip -q -d monasca_agent/collector/checks/libs/jmxfetch-0.3.0-jar-with-dependencies.jar org/apache/logging/log4j/core/lookup/JndiLookup.class org/apache/log4j/net/JMSAppender.class org/apache/log4j/jdbc/JDBCAppender.class org/apache/log4j/net/JMSSink.class org/apache/log4j/chainsaw"*"
unzip monasca_agent/collector/checks/libs/jmxterm-1.0-DATADOG-uber.jar WORLDS-INF/lib/log4j.jar
zip -q -d WORLDS-INF/lib/log4j.jar org/apache/logging/log4j/core/lookup/JndiLookup.class org/apache/log4j/net/JMSAppender.class org/apache/log4j/jdbc/JDBCAppender.class org/apache/log4j/net/JMSSink.class org/apache/log4j/chainsaw"*"
zip monasca_agent/collector/checks/libs/jmxterm-1.0-DATADOG-uber.jar WORLDS-INF/lib/log4j.jar

Change-Id: Id47ba9397e7fef1ac8622abb2a1691a260f4bc9c
2022-01-27 09:05:15 +00:00
..
checks Remove JMSAppender.class to avoid CVE-2021-4104, 2022-01-27 09:05:15 +00:00
checks_d Merge "Revert "Replace fnmatch with oslo.utils.fnmatch"" 2021-07-13 13:22:13 +00:00
virt vmware: Use oslo.vmware's get_moref_value() 2021-06-15 15:14:44 +00:00
__init__.py Renaming agent packages to reflect monasca 2014-12-19 09:22:03 -07:00
daemon.py Fix typo in log message 2021-06-09 09:49:31 +00:00
jmxfetch.py fix tox python3 overrides 2018-07-02 09:41:20 +02:00