SLF4J Backend that does NOT not interpret/expand log messages or arguments?

Viewed 64

What official or third party backends for SLF4J don't expand/interpret/etc, other than '{}' expansion, my log messages and run toString() on the arguments?

In the wake of CVE-2021-44228 I was not exactly happy to find that log4j was interpolating/interpreting/expanding my log messages and arguments. I didn't want this, didn't know log4j could do this and would never have expected it to be a default. It feels like a violation of what I expected from a logger.

Of the official backends:

  • Log4j 1.x is no longer supported and anything < 2.17 is asking for a head ache with the security policy folks who's technical knowledge goes no deeper than version must be >= 2.17
  • Logback?
  • Simple?
  • NoOp shouldn't (I hope) but it isn't very useful either

The only third party back end I've used is log4j 2 and we all know it does such expansion. Are there others?

I've written my own, can certainly deep dive on docs and audit code but I thought it worth asking both for my knowledge and any others feeling the same. Thanks!

0 Answers
Related