Hacker News new | ask | show | jobs
by juanbyrge 1657 days ago
I am guessing FANG engineers (and most engineers in general) would unanimously suggest "delete this ridiculous , ill-conceived JNDI integration ASAP. If people want JNDI integration, use a custom opt-in log4j appender. Don't let this shit be enabled by default". Yet that may not sit well with the log4j folks.
1 comments

Log4j taking user input to run and execute code is crazy. You don’t think it “sits well”?