Since the python logging package is based on PEP 282 and influenced by Apache's log4j system, does this package is impacted by the recent log4j vulnerabilities?
My knowledge of this particular module is limited so I'm hoping somebody here is a bit more familiar.
It's not affected (disclosure: I'm the maintainer of Python logging), because Python logging is not a direct port of log4j
, just influenced by it (in part). There are no equivalents in Python logging to the JNDI functionality built into log4j
, that led to the vulnerabilities in it.