What official or third party backends for SLF4J don't expand/interpret/etc, other than '{}' expansion, my log messages and run toString() on the arguments?
In the wake of CVE-2021-44228 I was not exactly happy to find that log4j was interpolating/interpreting/expanding my log messages and arguments. I didn't want this, didn't know log4j could do this and would never have expected it to be a default. It feels like a violation of what I expected from a logger.
Of the official backends:
- Log4j 1.x is no longer supported and anything < 2.17 is asking for a head ache with the security policy folks who's technical knowledge goes no deeper than version must be >= 2.17
- Logback?
- Simple?
- NoOp shouldn't (I hope) but it isn't very useful either
The only third party back end I've used is log4j 2 and we all know it does such expansion. Are there others?
I've written my own, can certainly deep dive on docs and audit code but I thought it worth asking both for my knowledge and any others feeling the same. Thanks!