java 程序Apache log4j JDBCAppender SQL注入漏洞(CVE-2022-23305)
问题

解决
<!-- 移除 Log4j 1.x -->
<!--
<dependency><groupId>log4j</groupId><artifactId>log4j</artifactId><version>1.2.17</version>
</dependency>
--><!-- 添加 Log4j 2.x -->
<dependency><groupId>org.apache.logging.log4j</groupId><artifactId>log4j-core</artifactId><version>2.20.0</version>
</dependency>
<dependency><groupId>org.apache.logging.log4j</groupId><artifactId>log4j-api</artifactId><version>2.20.0</version>
</dependency>再验证打印日志有没有影响
