I would expect Logback to simply limit the JNDI namespace to java: which should be in the local VM and that's it. No more other URL providers, but local ones. Btw, this is actually contained in the fix in Log4J2.
Duly noted. Can you please provide a patch or maybe a a POC? |