Hi all
Does anyone know if BBTools/BBMap and Qualimap are affected by the log4j vulnerability announced on 09-Dec-2021
Probably GenoMax and/or Brian Bushnell might be able to answer for BBMap
https://github.com/nf-core/rnaseq/issues/734#issuecomment-995031975
Thanks in advance
2 answers
no, unless the tools are used as a library in a web server.
It's worth noting picard.jar and abra.jar are affected (even though as Pierre L says, these are unlikely to be attacked on most systems).
If you're responsible for systems, esp web servers, it would pay to upgrade by downloading the latest jar and removing the older ones.
Not sure how bad a problem this could be with Galaxy webservers for example, where picard is used widely.
Log in to answer this question.